CVE-2026-55603: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') in chimurai http-proxy-middleware
CVE-2026-55603 is a CRLF injection vulnerability in the chimurai http-proxy-middleware for Node.js. The issue occurs in versions from 3.0.4 until 3.0.7 and 4.1.1, specifically in the fixRequestBody() helper when handling multipart/form-data content types. The vulnerability allows an attacker to inject additional form parts by including CRLF sequences in request body keys or values, causing a desynchronization between the proxy's parsed request body and the backend's interpretation. This can lead to bypassing gateway-side validation and potentially injecting malicious parameters. The vulnerability has a CVSS 3.1 score of 7.5 (high severity).
AI Analysis
Technical Summary
The vulnerability in http-proxy-middleware arises from improper neutralization of CRLF sequences in multipart/form-data request bodies. The fixRequestBody() function rebuilds the request body by interpolating req.body keys and values directly into the multipart wire format without sanitizing CR/LF characters. An attacker can exploit this by inserting \r\n sequences in keys or values, which prematurely closes the current multipart section and injects new form parts. This causes a mismatch between the proxy's parsed request body and the backend's parsed parameters, potentially allowing attackers to bypass validation or inject unauthorized data. The issue affects versions from 3.0.4 up to but not including 3.0.7 and 4.1.1. No explicit patch or remediation level is stated in the provided data.
Potential Impact
An attacker can exploit this vulnerability to inject additional form parts into multipart/form-data requests, causing the backend server to process different parameters than those validated by the proxy. This can lead to parameter desynchronization across trust boundaries, potentially enabling unauthorized actions or data manipulation. The CVSS score of 7.5 indicates a high impact on integrity with limited impact on confidentiality and no impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description states that the vulnerability is fixed in versions 3.0.7 and 4.1.1, so upgrading to these or later versions is recommended once confirmed. Until then, avoid using vulnerable versions or apply any official fixes provided by the vendor. No vendor advisory content is provided to confirm the patch status or additional mitigation steps.
CVE-2026-55603: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') in chimurai http-proxy-middleware
Description
CVE-2026-55603 is a CRLF injection vulnerability in the chimurai http-proxy-middleware for Node.js. The issue occurs in versions from 3.0.4 until 3.0.7 and 4.1.1, specifically in the fixRequestBody() helper when handling multipart/form-data content types. The vulnerability allows an attacker to inject additional form parts by including CRLF sequences in request body keys or values, causing a desynchronization between the proxy's parsed request body and the backend's interpretation. This can lead to bypassing gateway-side validation and potentially injecting malicious parameters. The vulnerability has a CVSS 3.1 score of 7.5 (high severity).
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in http-proxy-middleware arises from improper neutralization of CRLF sequences in multipart/form-data request bodies. The fixRequestBody() function rebuilds the request body by interpolating req.body keys and values directly into the multipart wire format without sanitizing CR/LF characters. An attacker can exploit this by inserting \r\n sequences in keys or values, which prematurely closes the current multipart section and injects new form parts. This causes a mismatch between the proxy's parsed request body and the backend's parsed parameters, potentially allowing attackers to bypass validation or inject unauthorized data. The issue affects versions from 3.0.4 up to but not including 3.0.7 and 4.1.1. No explicit patch or remediation level is stated in the provided data.
Potential Impact
An attacker can exploit this vulnerability to inject additional form parts into multipart/form-data requests, causing the backend server to process different parameters than those validated by the proxy. This can lead to parameter desynchronization across trust boundaries, potentially enabling unauthorized actions or data manipulation. The CVSS score of 7.5 indicates a high impact on integrity with limited impact on confidentiality and no impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description states that the vulnerability is fixed in versions 3.0.7 and 4.1.1, so upgrading to these or later versions is recommended once confirmed. Until then, avoid using vulnerable versions or apply any official fixes provided by the vendor. No vendor advisory content is provided to confirm the patch status or additional mitigation steps.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:31:22.444Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a39a0f6eed863c81e6b0296
Added to database: 06/22/2026, 20:54:14 UTC
Last enriched: 06/22/2026, 21:09:06 UTC
Last updated: 06/23/2026, 01:50:42 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.