CVE-2022-32215

Source
https://cve.org/CVERecord?id=CVE-2022-32215
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-32215.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-32215
Aliases
Downstream
ALPINE (1)
AZL (2)
BELL (1)
CGA (2)
CLEANSTART (14)
DEBIAN (1)
MGASA (1)
OESA (1)
openSUSE (2)
RHSA (5)
RLSA (3)
SUSE (13)
UBUNTU (1)
Related
Published
2022-07-14T00:00:00Z
Modified
2026-07-17T20:57:46Z
Summary
[none]
Details

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

Database specific
{
    "cna_assigner":  "hackerone",
    "cwe_ids":  [
        "CWE-444"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32215.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "4.0"
                },
                {
                    "fixed":  "4.*"
                },
                {
                    "introduced":  "5.0"
                },
                {
                    "fixed":  "5.*"
                },
                {
                    "introduced":  "6.0"
                },
                {
                    "fixed":  "6.*"
                },
                {
                    "introduced":  "7.0"
                },
                {
                    "fixed":  "7.*"
                },
                {
                    "introduced":  "8.0"
                },
                {
                    "fixed":  "8.*"
                },
                {
                    "introduced":  "9.0"
                },
                {
                    "fixed":  "9.*"
                },
                {
                    "introduced":  "10.0"
                },
                {
                    "fixed":  "10.*"
                },
                {
                    "introduced":  "11.0"
                },
                {
                    "fixed":  "11.*"
                },
                {
                    "introduced":  "12.0"
                },
                {
                    "fixed":  "12.*"
                },
                {
                    "introduced":  "13.0"
                },
                {
                    "fixed":  "13.*"
                },
                {
                    "introduced":  "14.0"
                },
                {
                    "fixed":  "14.20.1"
                },
                {
                    "introduced":  "15.0"
                },
                {
                    "fixed":  "15.*"
                },
                {
                    "introduced":  "16.0"
                },
                {
                    "fixed":  "16.17.1"
                },
                {
                    "introduced":  "17.0"
                },
                {
                    "fixed":  "17.*"
                },
                {
                    "introduced":  "18.0"
                },
                {
                    "fixed":  "18.9.1"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/nodejs/node

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/node
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "14.0.0"
        },
        {
            "last_affected":  "14.14.0"
        },
        {
            "introduced":  "14.15.0"
        },
        {
            "fixed":  "14.20.0"
        },
        {
            "introduced":  "16.0.0"
        },
        {
            "last_affected":  "16.12.0"
        },
        {
            "introduced":  "16.13.0"
        },
        {
            "fixed":  "16.16.0"
        },
        {
            "introduced":  "18.0.0"
        },
        {
            "fixed":  "18.5.0"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v14.*
v14.15.0
v14.15.1
v14.15.2
v14.15.3
v14.15.4
v14.15.5
v14.16.0
v14.16.1
v14.17.0
v14.17.1
v14.17.2
v14.17.3
v14.17.4
v14.17.5
v14.17.6
v14.18.0
v14.18.1
v14.18.2
v14.18.3
v14.19.0
v14.19.1
v14.19.2
v14.19.3
v16.*
v16.13.0
v16.13.1
v16.13.2
v16.14.0
v16.14.1
v16.14.2
v16.15.0
v16.15.1
v18.*
v18.0.0
v18.1.0
v18.2.0
v18.3.0
v18.4.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-32215.json"