(CVE-2026-55603) http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` LTS
envgap__angular__angular-cli-33534-pr33537
01 / FAILURE SIGNATURE
As reported upstream
### Exception or Error
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
31345b6154ef3189c084421af2d66b4676762bfb- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
angular/angular-cli #33534 · read the original issue
### Command build ### Is this a regression? - [ ] Yes, this behavior used to work in the previous version ### The previous version in which this bug was not present was _No response_ ### Description CVE-2026-55603 Impact When the preconditions hold, an attacker injects/overrides multipart fields seen only by the backend: Validation / access-control bypass bypass gateway-side field checks (demonstrated below: a gateway that forbids role=admin is bypassed; backend grants admin). Parameter tampering add or overwrite fields the backend trusts (IDs, flags, prices). File-part injection inject a filename="..." part into the upstream multipart stream. Upgrade http-proxy-middleware from 3.0.5 to 3.0.7 to fix the vulnerability. ### Minimal Reproduction N/A Angular version 20.3.x ### Exception or Error ```text ``` ### Your Environment ```text Angular version 20.3.x ``` ### Anything else relevant? _No response_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]