296,733
Total vulnerabilities in the database
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
| Software | From | Fixed in |
|---|---|---|
| llhttp / llhttp | - | 2.1.4 |
| llhttp / llhttp | 3.0.0 | 6.0.6 |
| oracle / graalvm | 21.3.0 | 21.3.0.x |
| oracle / graalvm | 20.3.4 | 20.3.4.x |
| debian / debian_linux | 11.0 | 11.0.x |