5.8
CVSSv2

CVE-2021-22960

Published: 03/11/2021 Updated: 20/01/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A security issue has been found in Node.js prior to 16.11.1, 14.18.1 and 12.22.7. The parser ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

llhttp llhttp

oracle graalvm 21.3.0

oracle graalvm 20.3.4

debian debian linux 11.0

Vendor Advisories

Synopsis Moderate: nodejs:14 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Secu ...
Synopsis Moderate: rh-nodejs12-nodejs security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-nodejs12-nodejs is now available for Red Hat Software CollectionsRed Hat Pro ...
Multiple vulnerabilities were discovered in Nodejs, which could result in HTTP request smuggling, a bypass of certificate verification or prototype pollution For the stable distribution (bullseye), these problems have been fixed in version 122212~dfsg-1~deb11u1 We recommend that you upgrade your nodejs packages For the detailed security statu ...
No description is available for this CVE ...
A security issue has been found in Nodejs before versions 16111, 14181 and 12227 The parser ignores chunk extensions when parsing the body of chunked requests This leads to HTTP Request Smuggling (HRS) under certain conditions ...
An HTTP Request Smuggling (HRS) vulnerability was found in the llhttp library, used by NodeJS Spaces as part of the header names were accepted as valid In situations where HTTP conversations are being proxied (such as proxy, reverse-proxy, load-balancer), an attacker can use this flaw to inject arbitrary messages through the proxy The highest t ...
ALAS-2022-214 Amazon Linux 2022 Security Advisory: ALAS-2022-214 Advisory Release Date: 2022-12-06 16:41 Pacific ...