CVE-2026-55602: Chimurai HTTP-Proxy-Middleware

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.

Affected products

  • Chimurai HTTP-Proxy-Middleware: from 0.16.0, before 2.0.10 (fixed in 2.0.10); from 3.0.0, before 3.0.6 (fixed in 3.0.6); from 4.0.0, before 4.1.0 (fixed in 4.1.0)

Published 2026-06-22. Last modified 2026-06-26.