http-proxy-middleware
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting http-proxy-middlewarepage 1 of 1
- CVE-2024-21536HIGHCVSS 7.5EG 7.5fixed in 2.0.7 or 3.0.3, by version range2024-10-19
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process an…
- CVE-2025-32996MEDIUMCVSS 4.0EG 4.0fixed in 2.0.8 or 3.0.4, by version range2025-04-15
In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
- CVE-2025-32997MEDIUMCVSS 4.0EG 4.0fixed in 2.0.9 or 3.0.5, by version range2025-04-15
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
- CVE-2026-55602HIGHCVSS 8.6EG 8.6fixed in 3.0.6, 4.1.0 or 2.0.10, by version range2026-06-18
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses una…
- CVE-2026-55603HIGHCVSS 7.5EG 7.5fixed in 3.0.7 or 4.1.1, by version range2026-06-18
http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Cont…
Check whether http-proxy-middleware is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for http-proxy-middleware CVEs against the assets you own.
Book a Demo →