CVE-2025-32997

MEDIUM4.0EPSS 0.06%

http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed

Published: 4/15/2025Modified: 2/4/2026
Also known as:GHSA-9gqv-wp59-fq42CGA-9chp-qw69-74c8

Description

In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

References (6)