{"id":"CVE-2023-28155","aliases":["GHSA-p8p7-x288-28g6"],"url":"https://o3.security/vulnerability/CVE-2023-28155","summary":"Server-Side Request Forgery in Request","details":"The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\n\nNOTE: The `request` package is no longer supported by the maintainer.","published":"2023-03-16T00:00:00Z","modified":"2026-08-12T03:51:12.637054182Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"request","fixedVersion":null},{"ecosystem":"npm","name":"@cypress/request","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/request/request/pull/3444","label":"request/request#3444"},"references":[{"type":"WEB","url":"https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28155.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28155"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230413-0007/"},{"type":"REPORT","url":"https://github.com/request/request/issues/3442"},{"type":"FIX","url":"https://github.com/request/request/pull/3444"},{"type":"WEB","url":"https://github.com/cypress-io/request/pull/28"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/2500"},{"type":"WEB","url":"https://github.com/cypress-io/request/commit/c5bcf21d40fb61feaff21a0e5a2b3934a440024f"},{"type":"WEB","url":"https://github.com/cypress-io/request/blob/master/lib/redirect.js#L116"},{"type":"WEB","url":"https://github.com/cypress-io/request/releases/tag/v3.0.0"},{"type":"PACKAGE","url":"https://github.com/request/request"},{"type":"WEB","url":"https://github.com/request/request/blob/master/lib/redirect.js#L111"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230413-0007"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.637054182Z"}}