← All tasks
javascriptangular/angular-cli #33534Not a task: not reproduced

(CVE-2026-55603) http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` LTS

envgap__angular__angular-cli-33534-pr33537

01 / FAILURE SIGNATURE

As reported upstream

### Exception or Error
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
31345b6154ef3189c084421af2d66b4676762bfb
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

angular/angular-cli #33534 · read the original issue
### Command

build

### Is this a regression?

- [ ] Yes, this behavior used to work in the previous version

### The previous version in which this bug was not present was

_No response_

### Description

CVE-2026-55603

Impact

When the preconditions hold, an attacker injects/overrides multipart fields seen only by the backend:
Validation / access-control bypass bypass gateway-side field checks (demonstrated below: a gateway that forbids role=admin is bypassed; backend grants admin).
Parameter tampering add or overwrite fields the backend trusts (IDs, flags, prices).
File-part injection inject a filename="..." part into the upstream multipart stream.

Upgrade http-proxy-middleware from 3.0.5 to 3.0.7 to fix the vulnerability.

### Minimal Reproduction

N/A
Angular version 20.3.x

### Exception or Error

```text

```

### Your Environment

```text
Angular version 20.3.x
```

### Anything else relevant?

_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]