The one-liner node.js proxy middleware for connect, express, next.js and more
92%
Total Score
62
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-32996 http-proxy-middleware is vulnerable to Always-Incorrect Control Flow Implementation in versions 3.0.0 - 3.0.4 and 1.3.0 - 2.0.8. | 1.3.0 - 2.0.83.0.0 - 3.0.4 | Medium |
CVE-2025-32997 http-proxy-middleware is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 3.0.0 - 3.0.5 and 1.3.0 - 2.0.9. | 1.3.0 - 2.0.93.0.0 - 3.0.5 | Medium |
CVE-2024-21536 http-proxy-middleware is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 2.0.7 and 3.0.0 - 3.0.3. | 0.0.0 - 2.0.73.0.0 - 3.0.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.4.3 | — | — |
httpxy Version ^0.5.1 | — | — |
is-glob Version ^4.0.3 | — | — |
micromatch Version ^4.0.8 | — | — |
is-plain-obj Version ^4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant