Loading HuntDB...

GHSA-px8h-5r3g-hj68

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

Related CVEs

Key Information

GHSA ID
GHSA-px8h-5r3g-hj68
Published
May 24, 2022 7:19 PM
Last Modified
May 24, 2022 7:19 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 28, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.