Vendorschimuraihttp-proxy-middlewareall versions
Vulnerabilities

chimurai http-proxy-middleware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-55602
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
Published 2026-06-22 · Analyzed
8.6EPSS 0.004
CVE-2024-21536
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
Published 2024-10-19 · Modified
7.7EPSS 0.010
CVE-2026-55603
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
Published 2026-06-22 · Analyzed
7.5EPSS 0.003
CVE-2025-32997
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
Published 2025-04-15 · Analyzed
5.3EPSS 0.005
CVE-2025-32996
In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
Published 2025-04-15 · Analyzed
5.3EPSS 0.005