GHSA-5689-v88g-g6rv
GitHub Security Advisory
llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
The llhttp parser in the http module in Node.js v17.x does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
Impacts:
- All versions of the nodejs 18.x, 16.x, and 14.x releases lines.
- llhttp v6.0.7 and llhttp v2.1.5 contains the fixes that were updated inside Node.js
Affected Packages
npm
llhttp
Affected versions:
0
(fixed in 6.0.7)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: September 21, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.