GHSA-rc2m-q589-vpqx
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: September 21, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.