pkg:npm/http-proxy-middleware
5 total CVEsHIGH2MEDIUM2
✅ Check your installed version
All known vulnerabilities
HIGH7.5CVE-2026-55603http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` >= 3.0.4, < 3.0.7
from 0, < 2.0.7
MEDIUM4.0CVE-2025-32996http-proxy-middleware can call writeBody twice because "else if" is not used >= 1.3.0, < 2.0.8
MEDIUM4.0http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
>= 1.3.0, < 2.0.9
—http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
>= 3.0.0, < 3.0.6