Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7910
HistoryNov 30, 2018 - 5:56 a.m.

HTTP Request Smuggling

2018-11-3005:56:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

48.7%

Node.js is vulnerable to HTTP request smuggling. Improper parsing of the path option of an HTTP request allows for a remote attacker to smuggle an HTTP request using Unicode data within the HTTP request, potentially bypassing existing access controls.