Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.74% | — | Fastify/http-proxy | 3/9/2026 | 9/9/2026 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects… | |
| Analizada | Crítica (10) | 0.44% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the… | |
| Analizada | Crítica (10) | 0.50% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so… | |
| Analizada | Alta (7.5) | 0.29% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 24/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it rebuilds the body with… | |
| Analizada | Media (6.9) | 0.38% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 26/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result,… | |
| Modificada | Crítica (9) | 0.56% | — | Fastify/http-proxyFastify Reply-from | 15/4/2026 | 15/7/2026 | @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection… | |
| Analizada | Media (5.3) | 0.47% | — | Chimurai Http-proxy-middleware | 15/4/2025 | 17/6/2026 | En http-proxy-middleware anterior a 2.0.9 y 3.x anterior a 3.0.5, fixRequestBody continúa incluso si bodyParser ha fallado. | |
| Analizada | Media (5.3) | 0.46% | — | Chimurai Http-proxy-middleware | 15/4/2025 | 17/6/2026 | En http-proxy-middleware anterior a 2.0.8 y 3.x anterior a 3.0.4, writeBody se puede llamar dos veces porque no se utiliza "else if". | |
| Modificada | Alta (7.7) | 1.0% | — | Chimurai Http-proxy-middleware | 19/10/2024 | 1/8/2026 | Las versiones del paquete http-proxy-middleware anteriores a la 2.0.7, a la 3.0.0 y a la 3.0.3 es vulnerable a un ataque de denegación de servicio (DoS) debido a un error UnhandledPromiseRejection generado por micromatch. Un atacante podría matar el proceso Node.js y bloquear el servidor al realizar solicitudes a… | |
| Modificada | Crítica (9.8) | 1.4% | — | Http-proxy-agent Project Http-proxy-agentFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux | 19/3/2021 | 17/6/2026 | Se encontró un fallo en http-proxy-agent, versiones anteriores a 2.1.0. Se detectó que http-proxy-agent pasa una opción de autenticación al constructor de Buffer sin un saneamiento apropiado. Esto podría resultar en una Denegación de Servicio mediante el uso de todos los recursos de CPU disponibles y la… | |
| Modificada | Crítica (9.8) | 1.6% | — | Fastify-http-proxy Project Fastify-http-proxy | 2/3/2021 | 17/6/2026 | fastify-http-proxy es un paquete npm que es un plugin fastify para enviar sus peticiones http a otro servidor, con hooks. Al diseñar una URL específica, es posible escapar el prefijo del servicio del backend proxy. Si la URL base del servidor proxy es "/pub/", un usuario espera que no sea posible acceder a… | |
| Modificada | Alta (7.5) | 1.2% | — | Http-proxy.js Project Http-proxy.js | 7/6/2018 | 17/6/2026 | "http-proxy.js" era un módulo malicioso publicado para secuestrar variables de entorno. Ha sido retirado por npm. | |
| Modificada | Alta (7.5) | 1.7% | — | Http-proxy Project Http-proxy | 4/6/2018 | 17/6/2026 | Http-proxy es una biblioteca de proxying. Debido a la forna en la que se gestionan los errores en las versiones anteriores a la 0.7.0, un atacante que fuerce un error podría provocar el cierre inesperado del servidor, lo que desencadena una denegación de servicio (DoS). |