Vulnerability: SNYK-JS-INFLIGHT-6095116 (Medium) in transitive dependency 'inflight'
Author: jatin-chaudhary-psCreated Apr 16, 2025Updated Apr 16, 2025
Vulnerability Summary
Attribute | Value | Source
-- | -- | --
Snyk ID | SNYK-JS-INFLIGHT-6095116 | Snyk Advisory
Vulnerability Type | Missing Release of Resource after Effective Lifetime | Snyk Advisory
Severity | Medium (CVSS 6.2) | Snyk Advisory
Affected Package | inflight | Snyk Advisory
Fix Available | No (inflight is unmaintained) | Snyk Advisory
(Source:(https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116))
Context
This issue reports a medium-severity vulnerability (SNYK-JS-INFLIGHT-6095116) identified in the inflight package. This vulnerability is present in projects using bunyan because inflight is included as a transitive dependency.
Dependency Path
The specific dependency path identified (e.g., via Snyk scan or npm ls for [email protected]) is:
[email protected] -> [email protected] -> [email protected] -> [email protected] -> [email protected]
Source: trentm/node-bunyan