Логотип exploitDog
bind:"CVE-2025-23167"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-23167"

Количество 8

Количество 8

ubuntu логотип

CVE-2025-23167

4 месяца назад

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2025-23167

4 месяца назад

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-23167

4 месяца назад

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-23167

4 месяца назад

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hchw-qwx7-4w4c

4 месяца назад

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-10618

4 месяца назад

Уязвимость модели разрешений программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю обойти существующие ограничения безопасности и отправлять несанкционированные запросы

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02045-1

3 месяца назад

Security update for nodejs20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02039-1

3 месяца назад

Security update for nodejs20

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-23167

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-23167

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-23167

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-23167

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP ...

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-hchw-qwx7-4w4c

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVSS3: 6.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-10618

Уязвимость модели разрешений программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю обойти существующие ограничения безопасности и отправлять несанкционированные запросы

CVSS3: 6.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02045-1

Security update for nodejs20

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02039-1

Security update for nodejs20

3 месяца назад

Уязвимостей на страницу