CVE-2025-32997: Medium severity http-proxy-middleware http-proxy-middleware vulnerability
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/http-proxy-middlewareto a version that resolves this vulnerability.Fixed in 2.0.9 - Upgrade
Upgrade
npm/http-proxy-middlewareto a version that resolves this vulnerability.Fixed in 3.0.5 - Upgrade
Upgrade
http-proxy-middlewareto a version that resolves this vulnerability.Fixed in 2.0.9 - Upgrade
Upgrade
http-proxy-middlewareto a version that resolves this vulnerability.Fixed in 3.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32997?
CVE-2025-32997 is classified as a moderate severity vulnerability due to potential impacts on data integrity.
How do I fix CVE-2025-32997?
To fix CVE-2025-32997, upgrade http-proxy-middleware to version 2.0.9 or 3.0.5 or higher.
What are the affected versions of http-proxy-middleware for CVE-2025-32997?
CVE-2025-32997 affects versions prior to 2.0.9 and versions between 3.0.0 and 3.0.4 of http-proxy-middleware.
What happens if I don't address CVE-2025-32997?
Failing to address CVE-2025-32997 may result in improper handling of request bodies, potentially compromising application functionality.
Is CVE-2025-32997 patched in future releases?
Yes, CVE-2025-32997 has been patched in version 2.0.9 and 3.0.5 of http-proxy-middleware.