← back
CVE-2019-15605CWE-444

CVE-2019-15605

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 57%
exploitation probability
57%top 1% of all CVEs
observed exploitation
nono source reports it
In short

Node.js versions 10, 12, and 13 have a flaw in how they handle certain HTTP headers, allowing an attacker to sneak malicious content past security checks by sending a specially crafted request. This can lead to bypassing protections and delivering harmful payloads to users.

Technical detail

HTTP request smuggling vulnerability in Node.js 10, 12, and 13 exploits improper parsing of malformed transfer-encoding headers, allowing an attacker to inject additional HTTP requests that are processed by downstream servers or proxies. The attack vector requires crafting malicious HTTP requests; the vulnerability enables cache poisoning, session hijacking, or delivery of malicious content to end users.

Summary generated and translated by AI from the official description.
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Affected products
NodeJS · Node