The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-04-07T21:00:00

Updated: 2024-08-05T23:24:48.440Z

Reserved: 2016-02-03T00:00:00

Link: CVE-2016-2216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-04-07T21:59:02.790

Modified: 2024-11-21T02:48:03.707

Link: CVE-2016-2216

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-02-09T00:00:00Z

Links: CVE-2016-2216 - Bugzilla