CVE Database
/

CVE-2019-15605

Back to search

CVE-2019-15605

Published: Feb 7, 2020

Modified: Apr 30, 2025

PUBLISHED

Description

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

VendorProductVersions

NodeJS

Node

affected
4.0 - < 4.*
affected
5.0 - < 5.*
affected
6.0 - < 6.*
affected
7.0 - < 7.*
affected
8.0 - < 8.*

+5 more versions

Weaknesses (CWE)

References

FEDORA-2020-3838c8ea98
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-47efc31973
vendor-advisory
x_refsource_FEDORA
RHSA-2020:0573
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0579
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0597
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0598
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0602
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0293
vendor-advisory
x_refsource_SUSE
RHSA-2020:0703
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0707
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0708
vendor-advisory
x_refsource_REDHAT
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO
DSA-4669
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now