CVE-2021-22959

All FrameworksNode.jsCWE-444CVE-2021-22959

CVE-2021-22959

State: PUBLISHED · Published: 2021-11-15 · Updated: 2025-04-30 · Assigner: hackerone
Description
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/22xxx/CVE-2021-22959.json