Description
Versions of tunnel-agent before 0.6.0 are vulnerable to memory exposure.
This is exploitable if user supplied input is provided to the auth value and is a number.
Recommendation
Update the tunnel-agent package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.0
- Patched version(s): 0.6.0
References
Related Issues
- Memory exhaustion in SvelteKit remote form deserialization (experimental only) - Vulnerability
- devalue affected by CPU and memory amplification from sparse arrays - Vulnerability
- Potential memory exposure in dns-packet - CVE-2021-23386
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
You might also like:
- Tags:
- npm
- tunnel-agent
Anything's wrong? Let us know Last updated on January 09, 2023


