CVE-2019-15605
No sign of exploitation. No public exploitation artifact known so far.
Node.js versions 10, 12, and 13 have a flaw in how they handle certain HTTP headers, allowing an attacker to sneak malicious content past security checks by sending a specially crafted request. This can lead to bypassing protections and delivering harmful payloads to users.
HTTP request smuggling vulnerability in Node.js 10, 12, and 13 exploits improper parsing of malformed transfer-encoding headers, allowing an attacker to inject additional HTTP requests that are processed by downstream servers or proxies. The attack vector requires crafting malicious HTTP requests; the vulnerability enables cache poisoning, session hijacking, or delivery of malicious content to end users.