---
id: CVE-2025-67485
aliases:
  - GHSA-wx63-35hw-2482
  - PYSEC-2026-1596
title: HTTP/HTTPS Traffic Interception Bypass in mad-proxy
summary: HTTP/HTTPS Traffic Interception Bypass in mad-proxy
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
vendor: mad-proxy
product: mad-proxy
ecosystem: pip
affected:
  - mad-proxy <= 0.3
published: '2025-12-09'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-wx63-35hw-2482'
references:
  - url: >-
      https://github.com/machphy/mad-proxy/security/advisories/GHSA-wx63-35hw-2482
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67485'
  - url: 'https://github.com/machphy/mad-proxy'
tags:
  - osv
  - pip
epss: 0.00242
epssPercentile: 0.15643
ingestedAt: '2026-07-08T18:25:53.927Z'
---

## Overview

A vulnerability in mad-proxy versions <= 0.3 allows attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic.

## Affected packages

- `mad-proxy <= 0.3`

## Remediation

Refer to the advisory for the patched release.
