High severity8.6NVD Advisory· Published Jun 22, 2026· Updated Jun 26, 2026
CVE-2026-55602
CVE-2026-55602
Description
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
http-proxy-middlewarenpm | >= 3.0.0, < 3.0.6 | 3.0.6 |
http-proxy-middlewarenpm | >= 4.0.0, < 4.1.0 | 4.1.0 |
http-proxy-middlewarenpm | >= 0.16.0, < 2.0.10 | 2.0.10 |
Affected products
33cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*range: >=0.16.0,<2.0.10
- (no CPE)range: >=0.16.0,<2.0.10, >=2.0.10,<3.0.6, >=3.0.6,<4.1.0
- osv-coords31 versionspkg:apk/chainguard/argo-workflows-ui-3.6pkg:apk/chainguard/argo-workflows-ui-3.7pkg:apk/chainguard/argo-workflows-ui-4.0pkg:apk/chainguard/gitlab-rails-ce-18.11pkg:apk/chainguard/gitlab-rails-ce-19.3pkg:apk/chainguard/gitlab-rails-ce-fips-18.11pkg:apk/chainguard/gitlab-rails-ce-fips-19.3pkg:apk/chainguard/katib-earlystoppingpkg:apk/chainguard/katib-suggestion-hyperbandpkg:apk/chainguard/katib-suggestion-hyperoptpkg:apk/chainguard/katib-suggestion-nas-dartspkg:apk/chainguard/katib-suggestion-nas-enaspkg:apk/chainguard/katib-suggestion-optuna-enaspkg:apk/chainguard/katib-suggestion-pbt-enaspkg:apk/chainguard/katib-suggestion-skopt-enaspkg:apk/chainguard/katib-tfevent-metricscollectorpkg:apk/chainguard/kubeflow-pipelines-frontendpkg:apk/wolfi/argo-workflows-ui-3.7pkg:apk/wolfi/argo-workflows-ui-4.0pkg:apk/wolfi/katib-earlystoppingpkg:apk/wolfi/katib-suggestion-hyperbandpkg:apk/wolfi/katib-suggestion-hyperoptpkg:apk/wolfi/katib-suggestion-nas-dartspkg:apk/wolfi/katib-suggestion-nas-enaspkg:apk/wolfi/katib-suggestion-optuna-enaspkg:apk/wolfi/katib-suggestion-pbt-enaspkg:apk/wolfi/katib-suggestion-skopt-enaspkg:apk/wolfi/katib-tfevent-metricscollectorpkg:apk/wolfi/kubeflow-pipelines-frontendpkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Tumbleweed
< 3.6.19-r7+ 30 more
- (no CPE)range: < 3.6.19-r7
- (no CPE)range: < 3.7.15-r1
- (no CPE)range: < 4.0.6-r1
- (no CPE)range: < 18.11.6-r7
- (no CPE)range: < 19.3.1-r6
- (no CPE)range: < 18.11.7-r1
- (no CPE)range: < 19.3.1-r3
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 2.16.1-r9
- (no CPE)range: < 3.7.15-r1
- (no CPE)range: < 4.0.6-r1
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 2.16.1-r9
- (no CPE)range: < 17+673.b97ba64d6-160000.12.1
- (no CPE)range: < 24+0.a836cced5-52.1
Patches
Vulnerability mechanics
References
2- github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-64mm-vxmg-q3vjnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-64mm-vxmg-q3vjghsaADVISORY
News mentions
0No linked articles in our index yet.