View all vulnerabilities

CVE-2024-21536

Denial of service in http-proxy-middleware

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
7.5
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
http-proxy-middleware < 2.0.7; http-proxy-middleware >= 3.0.0 < 3.0.3
Severity
High
Ecosystem
JavaScript
Publish Date
October 19, 2024
Modified Date
October 22, 2024