CVE-2022-32215 Information

Description

The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

Reference

https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/ https://hackerone.com/reports/1501679

Share on: