CVE-2022-32215
npm/llhttp
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
All versions before 2.1.5, all versions starting from 6.0.0 before 6.0.7
Upgrade to version 2.1.5, 6.0.7, or above.
2022-07-26
source |