HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4669-1 nodejs security update
Ubuntu USN Ubuntu USN USN-6380-1 Node.js vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-04-30T22:24:23.404Z

Reserved: 2019-08-26T00:00:00

Link: CVE-2019-15605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-07T15:15:11.287

Modified: 2024-11-21T04:29:06.890

Link: CVE-2019-15605

cve-icon Redhat

Severity : Important

Publid Date: 2020-02-07T00:00:00Z

Links: CVE-2019-15605 - Bugzilla

cve-icon OpenCVE Enrichment

No data.