Chimurai's vulnerability footprint concentrates in its http-proxy-middleware product, a focused HTTP request-routing component deployed in Node.js and web-application environments. The recurring signal across its disclosures centers on control-flow and resource-handling weaknesses, including always-incorrect control flow implementation, improper checks for exceptional conditions, and uncontrolled resource consumption, which reflect the parsing and request-forwarding demands of proxy middleware. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chimurai over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55602HIGH http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or hos | Jun 22, 2026 | 8.6 | 34 | NO | NO |
CVE-2026-55603HIGH http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that wa | Jun 22, 2026 | 7.5 | 32 | NO | NO |
CVE-2024-21536HIGH Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown b | Oct 19, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-32997MEDIUM In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed. | Apr 15, 2025 | 5.3 | 17 | NO | NO |
CVE-2025-32996MEDIUM In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used. | Apr 15, 2025 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chimurai.
Media articles that mention a CVE ID that affects a product developed by Chimurai — matched by CVE ID, not by vendor name.