Total vulnerabilities in the database
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
Software | From | Fixed in |
---|---|---|
llhttp / llhttp | - | 2.1.5 |
llhttp / llhttp | 6.0.0 | 6.0.7 |
nodejs / node.js | 14.0.0 | 14.14.0.x |
nodejs / node.js | 16.0.0 | 16.12.0.x |
nodejs / node.js | 14.15.0 | 14.20.1 |
nodejs / node.js | 16.13.0 | 16.17.1 |
nodejs / node.js | 18.0.0 | 18.9.1 |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
fedoraproject / fedora | 37 | 37.x |
siemens / sinec_ins | 1.0-sp1 | 1.0-sp1.x |
siemens / sinec_ins | 1.0 | 1.0.x |
siemens / sinec_ins | 1.0-sp2 | 1.0-sp2.x |
debian / debian_linux | 11.0 | 11.0.x |
stormshield / stormshield_management_center | - | 3.3.2 |