Skip to content

[GHSA-64mm-vxmg-q3vj] http-proxy-middleware router host+path substring matching allows Host-header-driven backend routing bypass#8072

Open
G-Rath wants to merge 1 commit into
G-Rath/advisory-improvement-8072from
G-Rath-GHSA-64mm-vxmg-q3vj
Open

[GHSA-64mm-vxmg-q3vj] http-proxy-middleware router host+path substring matching allows Host-header-driven backend routing bypass#8072
G-Rath wants to merge 1 commit into
G-Rath/advisory-improvement-8072from
G-Rath-GHSA-64mm-vxmg-q3vj

Conversation

@G-Rath

@G-Rath G-Rath commented Jun 19, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
I backported the fix to v2: chimurai/http-proxy-middleware#1268

@github

github commented Jun 19, 2026

Copy link
Copy Markdown
Collaborator

Hi there @chimurai! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI review requested due to automatic review settings June 19, 2026 19:07
Copilot stopped work on behalf of G-Rath due to an error June 19, 2026 19:08
@github-actions github-actions Bot changed the base branch from main to G-Rath/advisory-improvement-8072 June 19, 2026 19:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GHSA-64mm-vxmg-q3vj advisory record to refine which http-proxy-middleware versions are affected, reflecting separate fixed versions across major release lines (including the newly backported v2 fix mentioned in the PR description).

Changes:

  • Adjusts the v3 affected range to start at 3.0.0 (previously 0.16.0) and keeps the v3 fix at 3.0.6.
  • Adds an additional affected range covering the v2 line (0.16.0 → fixed in 2.0.10).
  • Updates the advisory modified timestamp.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 27 to 31
{
"introduced": "0.16.0"
"introduced": "3.0.0"
},
{
"fixed": "3.0.6"
@chimurai

chimurai commented Jun 19, 2026

Copy link
Copy Markdown

LGTM.

Thanks for updating the affected versions @G-Rath

Ref: GHSA-64mm-vxmg-q3vj

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants