Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-64mm-vxmg-q3vj | http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass |
Thu, 25 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 23 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chimurai
Chimurai http-proxy-middleware |
|
| Vendors & Products |
Chimurai
Chimurai http-proxy-middleware |
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0. | |
| Title | http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass | |
| Weaknesses | CWE-187 CWE-20 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-23T14:18:06.403Z
Reserved: 2026-06-16T23:18:03.170Z
Link: CVE-2026-55602
Updated: 2026-06-23T14:17:26.133Z
No data.
OpenCVE Enrichment
Updated: 2026-06-25T14:30:06Z
Github GHSA