Back to search
CVE-2019-15605
Published: Feb 7, 2020
Modified: Apr 30, 2025
PUBLISHED
Description
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
| Vendor | Product | Versions |
|---|---|---|
NodeJS | Node | affected 4.0 - < 4.*affected 5.0 - < 5.*affected 6.0 - < 6.*affected 7.0 - < 7.*affected 8.0 - < 8.*+5 more versions |
Weaknesses (CWE)
References
FEDORA-2020-3838c8ea98
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-47efc31973
vendor-advisory
x_refsource_FEDORA
RHSA-2020:0573
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0579
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0597
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0598
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0602
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0293
vendor-advisory
x_refsource_SUSE
RHSA-2020:0703
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0707
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0708
vendor-advisory
x_refsource_REDHAT
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO
DSA-4669
vendor-advisory
x_refsource_DEBIAN
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://www.oracle.com//security-alerts/cpujul2021.html
x_refsource_MISC
https://nodejs.org/en/blog/release/v13.8.0/
x_refsource_CONFIRM
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/
x_refsource_CONFIRM
https://nodejs.org/en/blog/release/v10.19.0/
x_refsource_CONFIRM
https://nodejs.org/en/blog/release/v12.15.0/
x_refsource_CONFIRM
https://security.netapp.com/advisory/ntap-20200221-0004/
x_refsource_CONFIRM
https://hackerone.com/reports/735748
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now