CVE-2018-3739
Estado: ModificadaCrítica (9.1)—
https-proxy-agent en versiones anteriores a la 2.1.1 pasa la opción auth al constructor del búfer sin un saneamiento adecuado, lo que resulta en una denegación de servicio (DoS) y una fuga de memoria no inicializada en setups en donde un atacante podría enviar entradas tecleadas en el parámetro "auth" (p.ej., JSON).
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.01%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-400
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-3739",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "HackerOne",
"product": "https-proxy-agent node module",
"versions": [
{
"status": "affected",
"version": "Versions before 2.1.1"
}
]
}
]
}
],
"published": "2018-06-07T02:29:08.973",
"references": [
{
"url": "https://hackerone.com/reports/319532",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://hackerone.com/reports/319532",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON)."
},
{
"lang": "es",
"value": "https-proxy-agent en versiones anteriores a la 2.1.1 pasa la opción auth al constructor del búfer sin un saneamiento adecuado, lo que resulta en una denegación de servicio (DoS) y una fuga de memoria no inicializada en setups en donde un atacante podría enviar entradas tecleadas en el parámetro \"auth\" (p.ej., JSON)."
}
],
"lastModified": "2026-06-17T01:57:45.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:https-proxy-agent_project:https-proxy-agent:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "916937F5-B8D7-4632-8E50-EBE9D0EC19BE",
"versionEndExcluding": "2.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}