A security issue has been found in Node.js prior to 16.11.1, 14.18.1 and 12.22.7. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
llhttp llhttp |
||
oracle graalvm 20.3.4 |
||
oracle graalvm 21.3.0 |
||
debian debian linux 11.0 |