Releases24
Frequency3 months 1 week
Last Release
Cypress's fork of a simplified HTTP request client.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
<= 2.88.1, <= 2.88.2, < 3.0.06.1 MEDIUM

The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.