Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx63-35hw-2482

Опубликовано: 09 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

HTTP/HTTPS Traffic Interception Bypass in mad-proxy

A vulnerability in mad-proxy versions <= 0.3 allows attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic.

Пакеты

Наименование

mad-proxy

pip
Затронутые версииВерсия исправления

<= 0.3

Отсутствует

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at the time of publication.

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-693