VYPR

HTTP Proxy Middleware

by Chimurai

Source repositories

CVEs (5)

  • CVE-2026-55602HigJun 22, 2026
    risk 0.49cvss 8.6epss 0.00

    http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on…

  • CVE-2026-55603HigJun 22, 2026
    risk 0.42cvss 7.5epss 0.00

    http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it…

  • CVE-2024-21536HigOct 19, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to…

  • CVE-2025-32997MedApr 15, 2025
    risk 0.19cvss 4.0epss 0.00

    In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

  • CVE-2025-32996MedApr 15, 2025
    risk 0.19cvss 4.0epss 0.00

    In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.