CVE-2022-35256
05.12.2022, 22:15
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
Vendor | Product | Version |
---|---|---|
nodejs | node.js | 14.0.0 ≤ 𝑥 ≤ 14.14.0 |
nodejs | node.js | 14.15.0 ≤ 𝑥 < 14.20.1 |
nodejs | node.js | 16.0.0 ≤ 𝑥 ≤ 16.12.0 |
nodejs | node.js | 16.13.0 ≤ 𝑥 < 16.17.1 |
nodejs | node.js | 18.0.0 ≤ 𝑥 < 18.9.1 |
llhttp | llhttp | 𝑥 < 6.0.10 |
siemens | sinec_ins | 𝑥 < 1.0 |
siemens | sinec_ins | 1.0 |
siemens | sinec_ins | 1.0:sp1 |
siemens | sinec_ins | 1.0:sp2 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases