6.4
CVSSv2

CVE-2021-22959

Published: 15/11/2021 Updated: 09/12/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A security issue has been found in Node.js prior to 16.11.1, 14.18.1 and 12.22.7. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

llhttp llhttp

oracle graalvm 21.3.0

oracle graalvm 20.3.4

debian debian linux 11.0

Vendor Advisories

Synopsis Moderate: nodejs:14 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Secu ...
Synopsis Moderate: rh-nodejs12-nodejs security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-nodejs12-nodejs is now available for Red Hat Software CollectionsRed Hat Pro ...
Multiple vulnerabilities were discovered in Nodejs, which could result in HTTP request smuggling, a bypass of certificate verification or prototype pollution For the stable distribution (bullseye), these problems have been fixed in version 122212~dfsg-1~deb11u1 We recommend that you upgrade your nodejs packages For the detailed security statu ...
A security issue has been found in Nodejs before versions 16111, 14181 and 12227 The http parser accepts requests with a space (SP) right after the header name before the colon This can lead to HTTP Request Smuggling (HRS) ...
An HTTP Request Smuggling (HRS) vulnerability was found in the llhttp library, used by NodeJS Spaces as part of the header names were accepted as valid In situations where HTTP conversations are being proxied (such as proxy, reverse-proxy, load-balancer), an attacker can use this flaw to inject arbitrary messages through the proxy The highest t ...
ALAS-2022-214 Amazon Linux 2022 Security Advisory: ALAS-2022-214 Advisory Release Date: 2022-12-06 16:41 Pacific ...