CVE-2024-27982

Source
https://cve.org/CVERecord?id=CVE-2024-27982
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27982.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-27982
Aliases
Downstream
ALPINE (1)
AZL (2)
BELL (1)
CGA (2)
CLEANSTART (13)
CLSA (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
OESA (5)
openSUSE (2)
RHSA (7)
RLSA (5)
ROOT (1)
SUSE (8)
UBUNTU (1)
Related
Withdrawn
2026-01-27T04:19:37Z
Published
2024-05-07T17:15:07Z
Modified
2026-04-16T00:08:42Z
Summary
[none]
Details

The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.

References

Affected packages