CVE-2025-32996

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*
cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*

History

21 Oct 2025, 14:43

Type Values Removed Values Added
First Time Chimurai http-proxy-middleware
Chimurai
CPE cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*
References () https://github.com/chimurai/http-proxy-middleware/commit/020976044d113fc0bcbbaf995e91d05e2829a145 - () https://github.com/chimurai/http-proxy-middleware/commit/020976044d113fc0bcbbaf995e91d05e2829a145 - Patch
References () https://github.com/chimurai/http-proxy-middleware/pull/1089 - () https://github.com/chimurai/http-proxy-middleware/pull/1089 - Issue Tracking
References () https://github.com/chimurai/http-proxy-middleware/releases/tag/v2.0.8 - () https://github.com/chimurai/http-proxy-middleware/releases/tag/v2.0.8 - Release Notes
References () https://github.com/chimurai/http-proxy-middleware/releases/tag/v3.0.4 - () https://github.com/chimurai/http-proxy-middleware/releases/tag/v3.0.4 - Release Notes

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) En http-proxy-middleware anterior a 2.0.8 y 3.x anterior a 3.0.4, writeBody se puede llamar dos veces porque no se utiliza "else if".

15 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 03:15

Updated : 2025-10-21 14:43


NVD link : CVE-2025-32996

Mitre link : CVE-2025-32996

CVE.ORG link : CVE-2025-32996


JSON object : View

Products Affected

chimurai

  • http-proxy-middleware
CWE
CWE-670

Always-Incorrect Control Flow Implementation