OsVault/npm/http-proxy-middleware
npm

http-proxy-middleware

6 known vulnerabilities · 0 critical · 1 high

CVE-2024-21536HIGH

Denial of service in http-proxy-middleware

Published Oct 19, 2024
CVE-2025-32997

http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed

Published Apr 15, 2025
CVE-2025-32996

http-proxy-middleware can call writeBody twice because "else if" is not used

Published Apr 15, 2025
GHSA-64mm-vxmg-q3vj

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

Published Jun 18, 2026
GHSA-gcq2-9pq2-cxqm

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

Published Jun 18, 2026
MAL-2024-1164

Malicious code in paysafe-gpf-as-http-proxy-middleware-body-replace (npm)

Published Apr 2, 2024
Check your entire dependency tree at onceRun dependency scan →