CVE Vulnerabilities

CVE-2025-32996

Always-Incorrect Control Flow Implementation

Published: Apr 15, 2025 | Modified: Oct 21, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because else if is not used.

Weakness

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Affected Software

NameVendorStart VersionEnd Version
Http-proxy-middlewareChimurai*2.0.8 (excluding)
Http-proxy-middlewareChimurai3.0.0 (including)3.0.4 (excluding)
Red Hat Developer Hub 1.6RedHatrhdh/rhdh-hub-rhel9:sha256:79618b38d6f02457954b227d538e238fdebbb72a220af5bd6be3cfab3ad0f262*
Red Hat Developer Hub 1.7RedHatrhdh/rhdh-hub-rhel9:sha256:aa3c5b50c65aee51b932fafcbf479ce54f15496cffc2744860bd9e135cce815c*

References