CVE Vulnerabilities

CVE-2025-32996

Always-Incorrect Control Flow Implementation

Published: Apr 15, 2025 | Modified: Apr 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because else if is not used.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

References