The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: hackerone
Published: 2022-07-14T00:00:00
Updated: 2025-04-30T22:24:45.103Z
Reserved: 2022-06-01T00:00:00
Link: CVE-2022-32213
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2022-07-14T15:15:08.287
Modified: 2024-11-21T07:05:56.257
Link: CVE-2022-32213
 Redhat
                        Redhat