Количество 35
Количество 35
BDU:2023-04893
Уязвимость программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнять атаку "контрабанда HTTP-запросов"
ALT-PU-2023-4642
ALT-PU-2023-4642: package `node` update to version 18.17.0-alt1
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3 only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16 v18 and v20
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly ...
ALT-PU-2025-2007
ALT-PU-2025-2007: package `node` update to version 16.20.3-alt1
GHSA-cggh-pq45-6h9x
llhttp vulnerable to HTTP request smuggling
RLSA-2023:4537
Moderate: nodejs:16 security, bug fix, and enhancement update
RLSA-2023:4536
Moderate: nodejs:18 security, bug fix, and enhancement update
ELSA-2023-4537
ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4536
ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4331
ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4330
ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-12944
ELSA-2023-12944: GraalVM Security update (IMPORTANT)
ELSA-2023-12943
ELSA-2023-12943: GraalVM Security update (IMPORTANT)
ELSA-2023-12942
ELSA-2023-12942: GraalVM Security update (IMPORTANT)
ELSA-2023-12941
ELSA-2023-12941: GraalVM Security update (IMPORTANT)
ELSA-2023-12940
ELSA-2023-12940: GraalVM Security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2023-04893 Уязвимость программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнять атаку "контрабанда HTTP-запросов" | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
ALT-PU-2023-4642 ALT-PU-2023-4642: package `node` update to version 18.17.0-alt1 | CVSS3: 7.5 | около 3 лет назад | ||
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20 | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20 | CVSS3: 7 | 4% Низкий | больше 3 лет назад | |
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20 | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3 only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16 v18 and v20 | CVSS3: 7.5 | 4% Низкий | 8 месяцев назад | |
CVE-2023-30589 The llhttp parser in the http module in Node v20.2.0 does not strictly ... | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
ALT-PU-2025-2007 ALT-PU-2025-2007: package `node` update to version 16.20.3-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
GHSA-cggh-pq45-6h9x llhttp vulnerable to HTTP request smuggling | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
RLSA-2023:4537 Moderate: nodejs:16 security, bug fix, and enhancement update | около 3 лет назад | |||
RLSA-2023:4536 Moderate: nodejs:18 security, bug fix, and enhancement update | почти 3 года назад | |||
ELSA-2023-4537 ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE) | около 3 лет назад | |||
ELSA-2023-4536 ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE) | около 3 лет назад | |||
ELSA-2023-4331 ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE) | около 3 лет назад | |||
ELSA-2023-4330 ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE) | около 3 лет назад | |||
ELSA-2023-12944 ELSA-2023-12944: GraalVM Security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2023-12943 ELSA-2023-12943: GraalVM Security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2023-12942 ELSA-2023-12942: GraalVM Security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2023-12941 ELSA-2023-12941: GraalVM Security update (IMPORTANT) | почти 3 года назад | |||
ELSA-2023-12940 ELSA-2023-12940: GraalVM Security update (IMPORTANT) | почти 3 года назад |
Уязвимостей на страницу