Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
This issue has been addressed in the following products: Red Hat OpenShift Service Mesh 2.6 for RHEL 8 Red Hat OpenShift Service Mesh 2.6 for RHEL 9 Via RHSA-2024:9627 https://access.redhat.com/errata/RHSA-2024:9627
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.5 Via RHSA-2025:3928 https://access.redhat.com/errata/RHSA-2025:3928
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.6 Via RHSA-2025:3929 https://access.redhat.com/errata/RHSA-2025:3929
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.7 Via RHSA-2025:3930 https://access.redhat.com/errata/RHSA-2025:3930
This issue has been addressed in the following products: RHODF-4.18-RHEL-9 Via RHSA-2025:4511 https://access.redhat.com/errata/RHSA-2025:4511
This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2025:8479 https://access.redhat.com/errata/RHSA-2025:8479
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2025:8510 https://access.redhat.com/errata/RHSA-2025:8510
This issue has been addressed in the following products: RHODF-4.15-RHEL-9 Via RHSA-2025:8544 https://access.redhat.com/errata/RHSA-2025:8544
This issue has been addressed in the following products: RHODF-4.14-RHEL-9 Via RHSA-2025:8551 https://access.redhat.com/errata/RHSA-2025:8551