High severity7.5NVD Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-25850
CVE-2022-25850
Description
The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/hoppscotch/proxyscotchGo | < 1.0.0 | 1.0.0 |
Affected products
2- github.com/hoppscotch/proxyscotchdescription
Patches
Vulnerability mechanics
References
4- github.com/hoppscotch/proxyscotch/commit/de67380f62f907f201d75854b76024ba4885fab7nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-GOLANG-GITHUBCOMHOPPSCOTCHPROXYSCOTCH-2435228nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5hjh-c26m-xw8wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25850ghsaADVISORY
News mentions
0No linked articles in our index yet.