VYPR
High severity8.6NVD Advisory· Published Jun 22, 2026· Updated Jun 26, 2026

CVE-2026-55602

CVE-2026-55602

Description

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
http-proxy-middlewarenpm
>= 3.0.0, < 3.0.63.0.6
http-proxy-middlewarenpm
>= 4.0.0, < 4.1.04.1.0
http-proxy-middlewarenpm
>= 0.16.0, < 2.0.102.0.10

Affected products

33

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.