GHSA-5492-mr68-4m2h
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: August 1, 2025 6:44 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.