{"id":"CVE-2026-55602","aliases":["GHSA-64mm-vxmg-q3vj"],"url":"https://o3.security/vulnerability/CVE-2026-55602","summary":"http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass","details":"http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is fixed in 2.0.10, 3.0.6, and 4.1.0.","published":"2026-06-22T15:58:08.699Z","modified":"2026-07-29T18:29:57.386365339Z","cvss":null,"epss":{"score":0.0037,"percentile":0.29692,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"http-proxy-middleware","fixedVersion":"3.0.6"},{"ecosystem":"npm","name":"http-proxy-middleware","fixedVersion":"4.1.0"},{"ecosystem":"npm","name":"http-proxy-middleware","fixedVersion":"2.0.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55602.json"},{"type":"ADVISORY","url":"https://github.com/chimurai/http-proxy-middleware/security/advisories/GHSA-64mm-vxmg-q3vj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55602"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-29T18:29:57.386365339Z"}}