GHSA-m6ch-gg5f-wxx3 high
HTTP Proxy header vulnerability
Affected range
ECOSYSTEM: introduced 0; fixed 1.0.4ECOSYSTEM: introduced 2.0.0; fixed 2.0.4>=2,<2.0.4|>0.7.1,<1.0.4Fixed versions: 1.0.4, 2.0.4
Asynchronous parallel HTTP/1.1 client built on the Amp concurrency framework
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
3.0.14
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
High
2 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 0; fixed 1.0.4ECOSYSTEM: introduced 2.0.0; fixed 2.0.4>=2,<2.0.4|>0.7.1,<1.0.4Fixed versions: 1.0.4, 2.0.4
Affected range
ECOSYSTEM: introduced 2; fixed 2.0.6ECOSYSTEM: introduced 0; fixed 1.0.6>=2,<2.0.6|<1.0.6Fixed versions: 2.0.6, 1.0.6