CVE-2025-32997

MEDIUM4.0EPSS 0.06%

http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed

發布日:2025/4/15修改日:2026/2/4
也稱為:GHSA-9gqv-wp59-fq42CGA-9chp-qw69-74c8

描述

In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

參考連結(6)