Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7518
HistorySep 24, 2018 - 5:08 a.m.

HTTP Response Splitting

2018-09-2405:08:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.004

Percentile

74.9%

nodejs is vulnerable to HTTP response splitting. This is due to a lack of validation for permitted characters in the reason argument in ServerResponse#writeHead() function. An attacker is able to inject arbitrary HTTP headers into the server response via the affected argument and perform HTTP response splitting attacks.