← Back to CVE List

CVE-2024-21536

Published: 2024-10-19T05:15Z
Last Modified: 2024-11-01T18:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt