Описание
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
A flaw was found in Node.js HTTP Agent. This vulnerability allows a client to accept a server response as valid even before the client has sent its request. This can lead to unexpected behavior and potentially information disclosure.
Отчет
This is a Low impact flaw in the Node.js HTTP Agent where a client may prematurely accept and process an HTTP response before its corresponding request has been fully sent. This could lead to a client misinterpreting data or entering an unexpected state. Exploitation requires high attack complexity, limiting the practical risk in most Red Hat deployments.
Меры по смягчению последствий
Limit outbound HTTP/1.1 from Node.js clients to trusted backend endpoints with egress firewall rules or network segmentation. Avoid keep-alive connection pools to untrusted hosts where operationally feasible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nodejs22 | Not affected | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Not affected | ||
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Not affected | ||
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Not affected | ||
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Not affected | ||
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Not affected | ||
| Red Hat Enterprise Linux 9 | nodejs:26/nodejs | Fix deferred | ||
| Red Hat Hardened Images | nodejs20 | Not affected | ||
| Red Hat Hardened Images | nodejs22 | Not affected | ||
| Red Hat Hardened Images | nodejs24 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js HTTP Agent can cause a client to accept as valid a r ...
EPSS
3.7 Low
CVSS3