Back to search
CVE-2020-8287
Published: Jan 6, 2021
Modified: Apr 30, 2025
PUBLISHED
Description
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
| Vendor | Product | Versions |
|---|---|---|
NodeJS | Node | affected 4.0 - < 4.*affected 5.0 - < 5.*affected 6.0 - < 6.*affected 7.0 - < 7.*affected 8.0 - < 8.*+7 more versions |
Weaknesses (CWE)
References
DSA-4826
vendor-advisory
FEDORA-2021-fb1a136393
vendor-advisory
GLSA-202101-07
vendor-advisory
FEDORA-2021-d5b2c18fe6
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now