CVE-2022-32214: vulnerability in NodeJS Node
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Node.js's HTTP parser accepts HTTP requests that don't follow the strict line-ending standard, allowing attackers to trick servers into processing malicious requests hidden in legitimate traffic.
The llhttp parser in Node.js http module fails to strictly validate CRLF delimiters in HTTP request boundaries, enabling HTTP Request Smuggling attacks where an attacker sends malformed requests that are interpreted differently by front-end and back-end proxies, potentially bypassing security controls.
In the same product, most dangerous first.