CVE Vulnerabilities

CVE-2025-32996

Always-Incorrect Control Flow Implementation

Published: Apr 15, 2025 | Modified: Apr 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
Ubuntu

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because else if is not used.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

References