5.3
CVE-2025-67485
- EPSS 0.21%
- Veröffentlicht 10.12.2025 00:08:39
- Zuletzt bearbeitet 09.03.2026 13:37:34
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at the time of publication.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.108 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-693 Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
https://github.com/machphy/mad-proxy/security/advisories/GHSA-wx63-35hw-2482