AnanthVivekanand/spotify-adblock

npm audit high severity vulnerability

swan11jf opened this issue · 1 comments

Denial of Service is shown as a high vulnerability

There's nothing that can be done about this right now since the issue is with http-proxy and affects all versions of it. We can't change anything on our side except change the proxy library, which is very time-consuming and isn't worth it right now.

Even then, the issue isn't very severe since most users will not be exposing the proxy to the outside world. Since most users will be using this on localhost or on their own closed network, no malicious actors should be able to actual perform a DoS (unless they happen to be on the network).