The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
2021-11-15T15:15:06.747
2024-11-21T05:51:01.317
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | llhttp | llhttp | < 2.1.4 | Yes |
| Application | llhttp | llhttp | < 6.0.6 | Yes |
| Application | oracle | graalvm | 20.3.4 | Yes |
| Application | oracle | graalvm | 21.3.0 | Yes |
| Operating System | debian | debian_linux | 11.0 | Yes |