CVE-2016-5325

Source
https://cve.org/CVERecord?id=CVE-2016-5325
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5325.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-5325
Downstream
Related
Published
2016-10-10T16:59:00.200Z
Modified
2026-05-17T11:53:59.868379199Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "12.0"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "suse:linux_enterprise"
        }
    ]
}
References

Affected packages