CVE-2025-32997

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 754

Summary

CVE-2025-32997 is a vulnerability affecting http-proxy-middleware versions before 2.0.9 and 3.x before 3.0.5. The issue lies within the "fixRequestBody" function, which continues processing even when "bodyParser" has failed. This might result in unexpected behavior, such as data leakage or unintended modification of requests. Attackers could potentially exploit this to inject malicious data or gain unauthorized access to sensitive information. Users are advised to update to the latest version of http-proxy-middleware to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share