Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-32215

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.885
EPSS Ranking 99.5%
CVSS Severity
CVSS v3 Score 6.5
References
Products affected by CVE-2022-32215


Contact Us

Shodan ® - All rights reserved