Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55602

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.

A flaw was found in http-proxy-middleware (before 2.0.10, 3.0.6, and 4.1.0). Router proxy-table host+path matching uses unanchored substring comparison on the Host header, so a crafted Host value that superstring-matches a configured key can route requests to an unintended backend.

Отчет

http-proxy-middleware is vulnerable to unintended backend routing when host+path proxy-table entries are configured. Unanchored substring matching on the attacker-controlled Host header can match a configured host+path key without an exact host match, sending the request to the wrong backend. Red Hat exposure is in Node.js dev/proxy stacks that bundle the middleware for local or console plugin routing, including OpenShift console plugins, Cryostat, GitOps, and AAP Lightspeed where reverse proxy rules use host+path selectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4http-proxy-middlewareNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleNot affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorNot affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2491470http-proxy-middleware: http-proxy-middleware: Unintended backend routing due to crafted Host header

EPSS

Процентиль: 30%
0.0037
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 месяца назад

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.

github
около 2 месяцев назад

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

suse-cvrf
8 дней назад

Security update for agama-web-ui

EPSS

Процентиль: 30%
0.0037
Низкий

6.5 Medium

CVSS3