CVE-2026-62985: CWE-248: Uncaught Exception in azu request-filtering-agent
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because Node.js http.request and http.get expect connection failures to be delivered asynchronously, the throw bypassed req.on('error') and became an uncaught exception that could terminate the application process. Hostnames resolved through the asynchronous lookup path were not affected by this error-delivery asymmetry. This issue is fixed in version 3.2.1.
AI Analysis
Technical Summary
The azu request-filtering-agent's RequestFilteringHttpAgent and RequestFilteringHttpsAgent implementations synchronously threw exceptions from createConnection when rejecting literal private IP addresses (e.g., 169.254.169.254 or 127.0.0.1) prior to version 3.2.1. Node.js http.request and http.get expect connection failures to be delivered asynchronously via error events, so the synchronous throw bypassed the req.on('error') handler and resulted in uncaught exceptions that could crash the application. Hostnames resolved asynchronously were not affected. This flaw is addressed by updating to version 3.2.1.
Potential Impact
An attacker or misconfiguration causing the agent to reject a request to a literal private IP address could trigger an uncaught exception, leading to application process termination. This results in a denial of service (DoS) condition. There is no impact on confidentiality or integrity. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the azu request-filtering-agent to version 3.2.1 or later, where this issue is fixed. No other mitigations are necessary as the fix addresses the root cause by delivering connection failures asynchronously as expected by Node.js.
CVE-2026-62985: CWE-248: Uncaught Exception in azu request-filtering-agent
Description
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because Node.js http.request and http.get expect connection failures to be delivered asynchronously, the throw bypassed req.on('error') and became an uncaught exception that could terminate the application process. Hostnames resolved through the asynchronous lookup path were not affected by this error-delivery asymmetry. This issue is fixed in version 3.2.1.
CVSS v3.1
Score 7.5high
Affected software
azu
request-filtering-agent
pkg:npm/azu/request-filtering-agentRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The azu request-filtering-agent's RequestFilteringHttpAgent and RequestFilteringHttpsAgent implementations synchronously threw exceptions from createConnection when rejecting literal private IP addresses (e.g., 169.254.169.254 or 127.0.0.1) prior to version 3.2.1. Node.js http.request and http.get expect connection failures to be delivered asynchronously via error events, so the synchronous throw bypassed the req.on('error') handler and resulted in uncaught exceptions that could crash the application. Hostnames resolved asynchronously were not affected. This flaw is addressed by updating to version 3.2.1.
Potential Impact
An attacker or misconfiguration causing the agent to reject a request to a literal private IP address could trigger an uncaught exception, leading to application process termination. This results in a denial of service (DoS) condition. There is no impact on confidentiality or integrity. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the azu request-filtering-agent to version 3.2.1 or later, where this issue is fixed. No other mitigations are necessary as the fix addresses the root cause by delivering connection failures asynchronously as expected by Node.js.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-14T22:48:09.781Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2d808f7a7c54106a8a016
Added to database: 09/22/2026, 19:33:28 UTC
Last enriched: 09/22/2026, 19:48:52 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.