@remix-run/express@2.15.0 vulnerabilities

Express server request handler for Remix

  • latest version

    2.16.5

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @remix-run/express package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    HTTP Request Smuggling

    @remix-run/express is an Express server request handler for Remix

    Affected versions of this package are vulnerable to HTTP Request Smuggling via Host or X-Forwarded-Host headers. An attacker can spoof the URL used in an incoming request's Host or X-Forwarded-Host header by passing in a URL pathname as the port of a URL.

    How to fix HTTP Request Smuggling?

    Upgrade @remix-run/express to version 2.16.3-pre.0 or higher.

    >=2.11.1 <2.16.3-pre.0