llhttp records
6 published records for vendor llhttp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2022-32214No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Medium6.5 | — | 82.5% | Jul 14, 2022 |
47Plan | CVE-2022-32215No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Medium6.5 | — | 68.8% | Jul 14, 2022 |
39Monitor | CVE-2022-32213No exploit | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Medium6.5 | — | 44.1% | Jul 14, 2022 |
27Monitor | CVE-2021-22959No exploit | The parser in accepts requests with a space (SP) right after the header name before the colon.llhttp · llhttp · CWE-444 | Medium6.5 | — | 3.2% | Nov 15, 2021 |
27Monitor | CVE-2022-35256No exploit | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.llhttp · llhttp · CWE-444 | Medium6.5 | — | 2.7% | Dec 5, 2022 |
27Monitor | CVE-2021-22960No exploit | The parse function in llhttp < 2.1.4 and < 6.0.6.llhttp · llhttp · CWE-444 | Medium6.5 | — | 2.5% | Nov 3, 2021 |
- CVE-2022-3221451Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
MediumCVSS 6.5No exploitEPSS 82%llhttp · llhttpJul 14, 2022
- CVE-2022-3221547Plan
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
MediumCVSS 6.5No exploitEPSS 69%llhttp · llhttpJul 14, 2022
- CVE-2022-3221339Monitor
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
MediumCVSS 6.5No exploitEPSS 44%llhttp · llhttpJul 14, 2022
- CVE-2021-2295927Monitor
The parser in accepts requests with a space (SP) right after the header name before the colon.
MediumCVSS 6.5No exploitEPSS 3%llhttp · llhttpNov 15, 2021
- CVE-2022-3525627Monitor
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.
MediumCVSS 6.5No exploitEPSS 3%llhttp · llhttpDec 5, 2022
- CVE-2021-2296027Monitor
The parse function in llhttp < 2.1.4 and < 6.0.6.
MediumCVSS 6.5No exploitEPSS 2%llhttp · llhttpNov 3, 2021