PT-2025-16283 · Unknown · Http-Proxy-Middleware

Chimurai

·

Published

2025-04-15

·

Updated

2025-10-21

·

CVE-2025-32996

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions http-proxy-middleware versions 2.0.7 and earlier, http-proxy-middleware versions 3.x before 3.0.4
Description The issue arises because writeBody can be called twice due to the absence of "else if". This can lead to information disclosure.
Recommendations For http-proxy-middleware version 2.0.7 and earlier, update to version 2.0.8 or later. For http-proxy-middleware version 3.x before 3.0.4, update to version 3.0.4 or later. As a temporary workaround, consider restricting the use of the writeBody function until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-32996
GHSA-4WWW-5P9H-95MH

Affected Products

Http-Proxy-Middleware