Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36300
HistoryJul 08, 2022 - 7:05 a.m.

HTTP Request Smuggling

2022-07-0807:05:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
http request smuggling
llhttp
vulnerability
transport-encoding header

EPSS

0.004

Percentile

72.6%

llhttp is vulnerable to HTTP request smuggling. The vulnerability exists because the http.js does not properly handle multi-line Transfer-Encoding headers, allowing an attacker to smuggle HTTP requests by submitting a malicious Transport-Encoding header.