PatchSiren

azu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH azu CVE published 2026-09-22

CVE-2026-62985

CVE-2026-62985 is a vulnerability in the request-filtering-agent, an HTTP(S) agent that blocks requests to private/reserved IP addresses. Prior to version 3.2.1, synchronous throws from createConnection occurred when rejecting literal private-IP hosts, bypassing req.on('error') and potentially terminating the application process. This issue is fixed in version 3.2.1.