[NPM:GHSA-5689-V88G-G6RV] llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

The llhttp parser in the http module in Node.js v17.x does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

Impacts:

  • All versions of the nodejs 18.x, 16.x, and 14.x releases lines.
  • llhttp v6.0.7 and llhttp v2.1.5 contains the fixes that were updated inside Node.js
Package Affected Version
pkg:npm/llhttp < 6.0.7
Package Fixed Version
pkg:npm/llhttp = 6.0.7
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:npm/llhttp llhttp < 6.0.7
Fixed pkg:npm/llhttp llhttp = 6.0.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...