Description
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5326-1 | nodejs security update |
Github GHSA |
GHSA-5689-v88g-g6rv | llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding |
Ubuntu USN |
USN-6491-1 | Node.js vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Llhttp
Subscribe
Llhttp
Subscribe
Nodejs
Subscribe
Node.js
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Eus
Subscribe
Rhel Software Collections
Subscribe
Siemens
Subscribe
Sinec Ins
Subscribe
Stormshield
Subscribe
Stormshield Management Center
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T22:24:45.103Z
Reserved: 2022-06-01T00:00:00.000Z
Link: CVE-2022-32213
No data.
Status : Modified
Published: 2022-07-14T15:15:08.287
Modified: 2024-11-21T07:05:56.257
Link: CVE-2022-32213
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA
Ubuntu USN