Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7849
HistoryNov 20, 2018 - 2:28 a.m.

HTTP Request Smuggling

2018-11-2002:28:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.005

Percentile

77.0%

node is vulnerable to HTTP request smuggling. Lack of validation for forbidden characters in the headers allows a remote attacker to send a request with a crafted Content-Length value to smuggle HTTP requests and bypass access controls.