The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
2021-11-03T20:15:08.247
2024-11-21T05:51:01.460
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | llhttp | llhttp | < 2.1.4 | Yes |
Application | llhttp | llhttp | < 6.0.6 | Yes |
Application | oracle | graalvm | 20.3.4 | Yes |
Application | oracle | graalvm | 21.3.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |