http-proxy-middleware vulnerabilities
CVEs whose affected-version data names the http-proxy-middleware package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-55602Mediumhttp-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
▾ Sunlithttp-proxy-middleware · http-proxy-middlewareEPSS 0.37%via GHSA
CVE-2026-55603High· 7.5http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
▾ Twilighthttp-proxy-middleware · http-proxy-middlewareEPSS 0.29%via GHSA
CVE-2024-21536High· 7.5Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process …
▾ Twilightchimurai · http-proxy-middlewareEPSS 1.0%via NVD