CVE-2022-32215: vulnerability in NodeJS Node
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Node.js's HTTP parser fails to properly process Transfer-Encoding headers that span multiple lines, allowing attackers to sneak hidden requests through proxies and firewalls by exploiting this misinterpretation.
The llhttp parser in Node.js versions before 14.20.1, 16.17.1, and 18.9.1 incorrectly parses multi-line Transfer-Encoding headers, enabling HTTP request smuggling attacks where an attacker sends a crafted request that is interpreted differently by frontend and backend servers, leading to request desynchronization and potential unauthorized access or cache poisoning.
In the same product, most dangerous first.