Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11356 | In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used. |
Github GHSA |
GHSA-4www-5p9h-95mh | http-proxy-middleware can call writeBody twice because "else if" is not used |
Tue, 21 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chimurai
Chimurai http-proxy-middleware |
|
| CPEs | cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chimurai
Chimurai http-proxy-middleware |
Tue, 01 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat rhdh |
|
| CPEs | cpe:/a:redhat:rhdh:1.6::el9 | |
| Vendors & Products |
Redhat
Redhat rhdh |
Tue, 15 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used. | |
| Weaknesses | CWE-670 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-15T03:55:51.136Z
Reserved: 2025-04-15T00:00:00.000Z
Link: CVE-2025-32996
Updated: 2025-04-15T03:55:47.264Z
Status : Analyzed
Published: 2025-04-15T03:15:18.210
Modified: 2025-10-21T14:43:20.087
Link: CVE-2025-32996
OpenCVE Enrichment
No data.
EUVD
Github GHSA