Skip to content
Noroxi

llhttp records

6 published records for vendor llhttp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 22

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

6 records
  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    MediumCVSS 6.5No exploitEPSS 82%

    llhttp · llhttpJul 14, 2022

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    MediumCVSS 6.5No exploitEPSS 69%

    llhttp · llhttpJul 14, 2022

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he

    MediumCVSS 6.5No exploitEPSS 44%

    llhttp · llhttpJul 14, 2022

  • The parser in accepts requests with a space (SP) right after the header name before the colon.

    MediumCVSS 6.5No exploitEPSS 3%

    llhttp · llhttpNov 15, 2021

  • The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF.

    MediumCVSS 6.5No exploitEPSS 3%

    llhttp · llhttpDec 5, 2022

  • The parse function in llhttp < 2.1.4 and < 6.0.6.

    MediumCVSS 6.5No exploitEPSS 2%

    llhttp · llhttpNov 3, 2021