CVE-2026-62985: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
Summary RequestFilteringHttpAgent / RequestFilteringHttpsAgent block requests to private IPs, but the blocking happens via a synchronous throw inside createConnection() for literal private-IP hostnames (e.g. 169.254.169.254, 127.0.0.1). Node.js's http.request / http.get expects createConnection to emit an error asynchronously; a synchronous throw instead escapes the caller's req.on('error', ...) handler entirely and becomes an unhandled exception that crashes the process.
Affected request-filtering-agent <= 3.2.0 (latest).
PoC (replicated live on 3.2.0) js const http = require('http'); const { RequestFilteringHttpAgent } = require('request-filtering-agent'); const agent = new RequestFilteringHttpAgent(); process.on('uncaughtException', e => { console.log('CRASH:', e.message); // fires — process dies }); const req = http.get({ hostname: '169.254.169.254', port: 80, agent }); req.on('error', e => { / never reached for literal IPs / }); Actual output: request-filtering-agent@3.2.0 synchronous throw escaping error event: UNCAUGHT EXCEPTION (process crash): DNS lookup 169.254.169.254(...) is not allowed. Because, It is private IP address. CRASH CONFIRMED: createConnection throws sync, bypasses req.on("error") Note: hostnames that resolve to private IPs (e.g. localhost) are handled via the async lookup path and correctly emit an error event — this asymmetry confirms the sync-throw is a defect.
Impact Any application using request-filtering-agent where an attacker can trigger an HTTP request to a literal private-IP (e.g. from a user-supplied URL that is pre-validated but still reaches http.get) will crash the Node.js process — full DoS.
Fix Instead of throwing synchronously in createConnection(), call callback(error) (the Node.js net.createConnection error-callback convention) or use process.nextTick(() => socket.destroy(error)) on the returned socket to emit the error asynchronously, allowing req.on('error') to handle it.
Other sources
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because Node.js http.request and http.get expect connection failures to be delivered asynchronously, the throw bypassed req.on('error') and became an uncaught exception that could terminate the application process. Hostnames resolved through the asynchronous lookup path were not affected by this error-delivery asymmetry. This issue is fixed in version 3.2.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/request-filtering-agentto a version that resolves this vulnerability.Fixed in 3.2.1 - Upgrade
Upgrade
request-filtering-agentto a version that resolves this vulnerability.Fixed in 3.2.1
Event History
Frequently Asked Questions
Who can trigger the process crash?
An unauthenticated remote party can trigger it if they can cause the application to issue a request through a vulnerable RequestFilteringHttpAgent or RequestFilteringHttpsAgent to a literal private or reserved IP address, such as 169.254.169.254 or 127.0.0.1.
Are requests to hostnames affected?
No. Hostnames that are resolved through the asynchronous lookup path are not affected by this error-delivery asymmetry; the issue applies to literal private-IP hosts.
Does attaching an error handler to the request prevent the crash?
No. The rejection was thrown synchronously from createConnection(), bypassing req.on('error') and potentially becoming an uncaught exception.
What version fixes the issue?
Upgrade request-filtering-agent to version 3.2.1 or later. Versions prior to 3.2.1 are affected.