Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36302
HistoryJul 08, 2022 - 8:18 a.m.

HTTP Request Smuggling

2022-07-0808:18:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.006 Low

EPSS

Percentile

78.5%

llhttp is vulnerable to http request smuggling. The vulnerability exists in the http function in http.ts due to a lack of validation and parsing of Transfer-Encoding headers which allows an attacker to smuggle HTTP requests.