CVE-2025-32996

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 670

Summary

CVE-2025-32996 is a vulnerability affecting the http-proxy-middleware library before version 2.0.8 and 3.x before 3.0.4. Due to an incorrect usage of conditional statements, the writeBody function can be triggered twice, leading to potential data overwriting and security breaches. This issue can result in unintended modifications to outgoing HTTP requests, posing a significant risk to applications that rely on the library for proxy functionality. To mitigate this vulnerability, it is recommended to upgrade to the latest version of http-proxy-middleware as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share