The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5170-1 | nodejs security update |
EUVD |
EUVD-2021-10084 | The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T22:24:37.284Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22959
No data.
Status : Modified
Published: 2021-11-15T15:15:06.747
Modified: 2024-11-21T05:51:01.317
Link: CVE-2021-22959
OpenCVE Enrichment
No data.
Debian DSA
EUVD