CVE-2025-32997 Information

Description

In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5 fixRequestBody proceeds even if bodyParser has failed.

Reference

https://github.com/chimurai/http-proxy-middleware/commit/1bdccbeec243850f1d2bb50ea0ff2151e725d67e https://github.com/chimurai/http-proxy-middleware/pull/1096 https://github.com/chimurai/http-proxy-middleware/releases/tag/v2.0.9 https://github.com/chimurai/http-proxy-middleware/releases/tag/v3.0.5

Share on: