ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

HTTP request smuggling vulnerability in Node.js (CVE-2022-35256)

mediumVulnerabilityimportance 35CVE-2022-35256

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-35256
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

NVD description · AI analysis pending
6.53% PoC
  • nodejs node.js
  • nodejs llhttp
  • nodejs sinec ins
  • +1 more
Full article50 words · extracted from helpnetsecurity.com · click to collapse

In this Help Net Security video, Austin Jones, Principal Software Engineer at ThreatX, explains what HTTP request smuggling is, and discusses a recently uncovered HTTP request smuggling vulnerability in Node.js (CVE-2022-35256).

This vulnerability allows an attacker to bypass security controls on the target server to conduct any nefarious activities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/04/http-request-smuggling-vulnerability-cve-2022-35256-video/