---
title: Security Bulletin NR18-08
source: https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-bulletin-nr18-08
---

## Summary

A security update for the Node.js agent fixes a vulnerability in the `https-proxy-agent` module.

**Release date:** Apr 12, 2018

**Vulnerability identifier:** NR18-08

**Priority:** Low

## Affected software [#affected]

The following New Relic agent versions are affected:

| Name          | Affected version | Notes | Remediated version                                                                             |
| ------------- | ---------------- | ----- | ---------------------------------------------------------------------------------------------- |
| Node.js agent | All              |       | [4.0.0](https://docs.newrelic.com/docs/release-notes/agent-release-notes/nodejs-release-notes) |

## Vulnerability information [#vuln-info]

The New Relic Node.js agent uses `https-proxy-agent` as an option to send data to the [New Relic collector](https://docs.newrelic.com/docs/using-new-relic/welcome-new-relic/getting-started/glossary#collector) via an HTTP or HTTPS proxy server. The Node.js agent used a version of this module which was vulnerable to Uninitialized Memory Exposure and Denial of Service. This fix updates the module to a version that is not vulnerable.

## Mitigating Circumstances [#workarounds]

Triggering this security vulnerability requires control of the agent proxy authentication configuration.

-   [Snyk: `https-proxy-agent`](https://snyk.io/vuln/npm:https-proxy-agent:20180402)
-   [HackerOne Report](https://hackerone.com/reports/319532)

## Workarounds

New Relic has not identified any workarounds for this vulnerability.

## Report security vulnerabilities to New Relic [#report]

New Relic is committed to the security of our customers and their data. If you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic's coordinated disclosure program. For more information, see [Reporting security vulnerabilities](https://docs.newrelic.com/docs/security/new-relic-security/data-privacy/reporting-security-vulnerabilities).

## For more help [#more_help]

Additional documentation resources include:.

-   [Upgrade the Node.js agent](https://docs.newrelic.com/docs/agents/nodejs-agent/installation-configuration/upgrade-nodejs-agent)
-   [NR Security](https://newrelic.com/security)
