VDB
Sign up
CRITICAL9.1

GHSA-5689-v88g-g6rv

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Quick fix

GHSA-5689-v88g-g6rv — llhttp: upgrade to the fixed version with the command below.

npm install llhttp@6.0.7

Details

The llhttp parser in the http module in Node.js v17.x does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

Impacts:

- All versions of the nodejs 18.x, 16.x, and 14.x releases lines. - llhttp v6.0.7 and llhttp v2.1.5 contains the fixes that were updated inside Node.js

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/llhttp
Introduced in: 0Fixed in: 6.0.7
Fixnpm install llhttp@6.0.7

References