CVE-2022-32214CWE-444

CVE-2022-32214: vulnerability in NodeJS Node

Published · Updated

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 82%
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
5 products (144 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux AppStream EUS (v.8.4) · Red Hat Software Collections for RHEL Workstation(v. 7) · Red Hat Software Collections for RHEL(v. 7)
Not affected
4 products (20 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Software Collections for RHEL Workstation(v. 7) · Red Hat Software Collections for RHEL(v. 7)
In short

Node.js's HTTP parser accepts HTTP requests that don't follow the strict line-ending standard, allowing attackers to trick servers into processing malicious requests hidden in legitimate traffic.

Technical detail

The llhttp parser in Node.js http module fails to strictly validate CRLF delimiters in HTTP request boundaries, enabling HTTP Request Smuggling attacks where an attacker sends malformed requests that are interpreted differently by front-end and back-end proxies, potentially bypassing security controls.

Summary generated and translated by AI from the official description.
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
Affected products
NodeJS · Node