Description
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5326-1 | nodejs security update |
Ubuntu USN |
USN-6491-1 | Node.js vulnerabilities |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Llhttp
Subscribe
Llhttp
Subscribe
Nodejs
Subscribe
Node.js
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Eus
Subscribe
Rhel Software Collections
Subscribe
Siemens
Subscribe
Sinec Ins
Subscribe
Stormshield
Subscribe
Stormshield Management Center
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T22:24:42.485Z
Reserved: 2022-06-01T00:00:00.000Z
Link: CVE-2022-32215
No data.
Status : Modified
Published: 2022-07-14T15:15:08.387
Modified: 2024-11-21T07:05:56.540
Link: CVE-2022-32215
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN