Total vulnerabilities in the database
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
Software | From | Fixed in |
---|---|---|
llhttp / llhttp | - | 2.1.4 |
llhttp / llhttp | 3.0.0 | 6.0.6 |
oracle / graalvm | 21.3.0 | 21.3.0.x |
oracle / graalvm | 20.3.4 | 20.3.4.x |
debian / debian_linux | 11.0 | 11.0.x |