Executive brief
http-proxy is a Node.js library that routes HTTP requests between clients and backend servers. Versions before 1.18.1 crash when receiving HTTP POST requests with large bodies if the proxy server modifies request headers, causing temporary service outages. An attacker can trigger the crash remotely without authentication, disrupting the proxy's availability.
Technical details
The vulnerability is an unhandled exception (ERR_HTTP_HEADERS_SENT) triggered when an HTTP request with a body larger than 1025 bytes is received and the proxy server calls proxyReq.setHeader() to modify request headers. The root cause is premature emission of the 'proxyReq' event before headers are finalized, allowing header modification after headers have already been sent to the destination. The attack is network-accessible and requires no authentication or user interaction; a simple POST request with a large payload triggers the crash. Affected versions prior to 1.18.1 are vulnerable; the fix was merged in May 2020 and checks for the 'expect' header before emitting the proxyReq event.
Affected products
- http-party http-proxy prior to 1.18.1
Timeline
- 2020-09-04: disclosed
- 2020-05-17: patched: Fix merged in PR #1447 (May 15, 2020), released as version 1.18.1