Lucene search

K
f5F5F5:K82567234
HistoryNov 22, 2022 - 5:02 p.m.

NodeJS vulnerability CVE-2022-32215

2022-11-2217:02:00
support.f5.com
14
nodejs
vulnerability
cve-2022-32215
llhttp parser
http request smuggling
multi-line transfer-encoding headers
impact
software

0.004 Low

EPSS

Percentile

72.7%

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). (CVE-2022-32215)

Impact

For products with Nonein the Versions known to be vulnerable column, there is no impact.

For products with ****** in the various columns, F5 is still researching the issue and will update this article after confirming the required information. F5 Support has no additional information about this issue.

CPENameOperatorVersion
big-ip spkeq