tiny-json-http@5.2.0 vulnerabilities

Minimalist `HTTP` client for `GET`, `POST`, `PUT`, `PATCH` and `DELETE` `JSON` payloads

Direct Vulnerabilities

Known vulnerabilities in the tiny-json-http package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Man-in-the-Middle (MitM)

tiny-json-http is a minimalist HTTP client for GET and POSTing JSON payloads.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM) attacks. It contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.

How to fix Man-in-the-Middle (MitM)?

Upgrade tiny-json-http to version 7.0.0 or higher.

<7.0.0