CVE-2025-32997
CVSS 3.1 Score 4 of 10 (medium)
Details
Published Apr 15, 2025
CWE ID 754
Summary
CVE-2025-32997 is a vulnerability affecting http-proxy-middleware versions before 2.0.9 and 3.x before 3.0.5. The issue lies within the "fixRequestBody" function, which continues processing even when "bodyParser" has failed. This might result in unexpected behavior, such as data leakage or unintended modification of requests. Attackers could potentially exploit this to inject malicious data or gain unauthorized access to sensitive information. Users are advised to update to the latest version of http-proxy-middleware to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.