6.5
CVSSv3

CVE-2022-32214

Published: 14/07/2022 Updated: 19/07/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

llhttp llhttp

nodejs node.js

debian debian linux 11.0

stormshield stormshield management center

Vendor Advisories

Multiple vulnerabilities were discovered in Nodejs, which could result in HTTP request smuggling, bypass of host IP address validation and weak randomness setup For the stable distribution (bullseye), these problems have been fixed in version 122212~dfsg-1~deb11u3 We recommend that you upgrade your nodejs packages For the detailed security st ...
Synopsis Moderate: nodejs:14 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated ...
Synopsis Moderate: nodejs:14 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat ...
Synopsis Moderate: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now availa ...
Synopsis Moderate: nodejs and nodejs-nodemon security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nodejs and nodejs-nodemon is now available for Red Hat Enterprise Linux 9Red Hat Produ ...
Synopsis Moderate: nodejs:16 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated ...
The llhttp parser in the http module in Nodejs does not strictly use the CRLF sequence to delimit HTTP requests This can lead to HTTP Request Smuggling (HRS) ...
ALAS-2023-286 Amazon Linux 2022 Security Advisory: ALAS-2023-286 Advisory Release Date: 2023-01-31 21:11 Pacific Advisory Updated Date: 2023-01-31 21:11 Pac ...