CVE-2021-22960
PoC —CVSS 3.1
6.5 medium
EPSS
2%p84
Published
()
Modified
Description
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
In the news0 stories
No ingested article mentions this CVE yet.