The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
2022-12-05T22:15:10.570
2025-04-24T14:15:32.277
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | ≤ 14.14.0 | Yes |
Application | nodejs | node.js | < 14.20.1 | Yes |
Application | nodejs | node.js | ≤ 16.12.0 | Yes |
Application | nodejs | node.js | < 16.17.1 | Yes |
Application | nodejs | node.js | < 18.9.1 | Yes |
Application | llhttp | llhttp | < 6.0.10 | Yes |
Application | siemens | sinec_ins | < 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Application | siemens | sinec_ins | 1.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |