WhisperX tag archive

#proxy

This page collects WhisperX intelligence signals tagged #proxy. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (7)

The Lab · 2026-03-29 14:27:04 · GitHub Issues

2. Sentinel Flags MEDIUM Severity DoS Risk in Axios Proxy Configuration

A critical security gap in the proxy's HTTP request handling has been identified, exposing the system to potential Denial of Service (DoS) attacks. The vulnerability stems from missing size and timeout boundaries on outbound requests made via the `axios` library. Without these limits, a malicious actor could force the ...

The Lab · 2026-04-02 15:27:26 · GitHub Issues

3. cc-switch Proxy CORS Misconfiguration: Any Website Can Silently Hijack User AI API Keys

A critical security flaw in the cc-switch local proxy server allows any website to silently hijack a user's AI API keys with a single click. The vulnerability stems from an overly permissive CORS (Cross-Origin Resource Sharing) policy configured in the proxy, which automatically injects the user's private API keys into...

The Lab · 2026-04-06 06:27:03 · GitHub Issues

4. Critical Proxy Module Flaw: No Request Validation Exposes Campus-Marketplace, CCPS-Portal to Malicious Payloads

A critical architectural flaw in the proxy module of a major campus services platform has been identified, creating a direct, unprotected pipeline for malicious payloads to reach downstream systems. The module, located in `src/proxy/`, acts as the central gateway between the user-facing Hub and critical backend service...

The Lab · 2026-04-07 11:27:17 · GitHub Issues

5. ContextForge Rust MCP Runtime Proxy Exposed Security Flaw: Non-Hex Server IDs Bypassed Validation, Served Global Scope

A security vulnerability in ContextForge's Rust MCP runtime proxy allowed unauthorized access by bypassing critical server validation. The flaw permitted non-hexadecimal server IDs—such as 'ndh45' or 'my-server'—to pass through the proxy without proper checks. These invalid IDs were forwarded to the Rust sidecar, but c...

The Lab · 2026-04-14 07:22:36 · GitHub Issues

6. Axios v1.15.0 Security Patch: Proxy Bypass Flaw in NO_PROXY Handling (CVE-2025-62718)

A critical security flaw in the widely-used Axios HTTP client library has been patched, exposing a proxy bypass vulnerability that could allow attackers to intercept sensitive internal traffic. The issue, tracked as CVE-2025-62718, stems from improper hostname normalization when checking `NO_PROXY` rules. Specifically,...

The Lab · 2026-04-14 15:22:53 · GitHub Issues

7. Tinyproxy 1.11.3 HTTP Request Parsing Desynchronization Vulnerability (CVE-2026-31842)

A critical vulnerability in Tinyproxy, tracked as CVE-2026-31842, exposes the proxy server to HTTP request parsing desynchronization attacks. The flaw stems from a case-sensitive comparison of the Transfer-Encoding header, allowing a remote, unauthenticated attacker to manipulate how the server interprets and forwards ...