ZeroHour

CVE-2022-32214

PoC
CVSS 3.1
6.5 medium
EPSS
82%p100
Published
()
Modified
Description

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

Vendors
llhttpnodejsdebianstormshield
Products
llhttp, node.js, debian linux, stormshield management center
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.