Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36305
HistoryJul 08, 2022 - 6:20 p.m.

HTTP Request Smuggling

2022-07-0818:20:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.002 Low

EPSS

Percentile

61.0%

llhttp is vulnerable to HTTP request smuggling. The vulnerability exists because the http.js does not properly handle the CRLF sequence, allowing an attacker to smuggle HTTP requests by submitting LF characters without CR.