Total vulnerabilities in the database
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
Software | From | Fixed in |
---|---|---|
llhttp / llhttp | - | 2.1.5 |
llhttp / llhttp | 6.0.0 | 6.0.7 |
nodejs / node.js | 18.0.0 | 18.5.0 |
nodejs / node.js | 14.15.0 | 14.20.0 |
nodejs / node.js | 16.13.0 | 16.16.0 |
nodejs / node.js | 14.0.0 | 14.14.0.x |
nodejs / node.js | 16.0.0 | 16.12.0.x |
debian / debian_linux | 11.0 | 11.0.x |
stormshield / stormshield_management_center | - | 3.3.0 |