CVE-2018-7159
published 2018-05-17CVE-2018-7159: The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
3.62%
88.3th percentile
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 8.11.1~dfsg-2 (bookworm) | nodejs 8.11.1~dfsg-2 (bookworm) |
| msrc | azl3_boost_1.83.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-http_parser_0.8.0-1_on_azure_linux_3.0 | — | — |
| nodejs | node.js | 4.0.0 – 4.1.2 | — |
| nodejs | node.js | >= 4.2.0 < 4.9.0 | 4.9.0 |
| nodejs | node.js | 6.0.0 – 6.8.1 | — |
| nodejs | node.js | >= 6.9.0 < 6.14.0 | 6.14.0 |
| nodejs | node.js | 8.0.0 – 8.8.1 | — |
| nodejs | node.js | >= 8.9.0 < 8.11.0 | 8.11.0 |
| nodejs | node.js | >= 9.0.0 < 9.10.0 | 9.10.0 |
| nodejs | nodejs | >= 0 < 8.11.1~dfsg-2 | 8.11.1~dfsg-2 |
| nodejs | nodejs | >= 0 < 8.11.1~dfsg-2 | 8.11.1~dfsg-2 |
| nodejs | nodejs | >= 0 < 8.11.1~dfsg-2 | 8.11.1~dfsg-2 |
| nodejs | nodejs | >= 0 < 8.11.1~dfsg-2 | 8.11.1~dfsg-2 |
| the_node.js_project | node.js | — | — |
| the_node.js_project | node.js | — | — |
| the_node.js_project | node.js | — | — |
| the_node.js_project | node.js | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP spe
vendor_msrc·2018-05-08·CVSS 5.3
CVE-2018-7159 [MEDIUM] CWE-115 The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP spe
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users cr
Red Hat
nodejs: HTTP parser allowed for spaces inside Content-Length header values
vendor_redhat·2018-03-08·CVSS 5.3
CVE-2018-7159 [MEDIUM] CWE-20 nodejs: HTTP parser allowed for spaces inside Content-Length header values
nodejs: HTTP parser allowed for spaces inside Content-Length header values
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of thi
Debian
CVE-2018-7159: nodejs - The HTTP parser in all current versions of Node.js ignores spaces in the `Conten...
vendor_debian·2018·CVSS 5.3
CVE-2018-7159 [MEDIUM] CVE-2018-7159: nodejs - The HTTP parser in all current versions of Node.js ignores spaces in the `Conten...
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users cr
GHSA
GHSA-87vg-5pwm-8x6w: The HTTP parser in all current versions of Node
ghsa_unreviewed·2022-05-13
CVE-2018-7159 [MEDIUM] CWE-20 GHSA-87vg-5pwm-8x6w: The HTTP parser in all current versions of Node
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users cr
OSV
CVE-2018-7159: The HTTP parser in all current versions of Node
osv·2018-05-17·CVSS 5.3
CVE-2018-7159 [MEDIUM] CVE-2018-7159: The HTTP parser in all current versions of Node
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users cr
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7159 nodejs: HTTP parser allowed for spaces inside Content-Length header values
bugzilla·2018-03-29·CVSS 5.3
CVE-2018-7159 [MEDIUM] CVE-2018-7159 nodejs: HTTP parser allowed for spaces inside Content-Length header values
CVE-2018-7159 nodejs: HTTP parser allowed for spaces inside Content-Length header values
The Node.js HTTP parser allowed for spaces inside Content-Length header values. Such values now lead to rejected connections in the same way as non-numeric values.
References:
https://github.com/nodejs/node/blob/master/doc/changelogs/CHANGELOG_V8.md
Discussion:
Created nodejs tracking bugs for this issue:
Affects: fedora-all [bug 1562027]
Affects: epel-all [bug 1562026]
---
Upstream fix: https://github.com/nodejs/node/commit/c39167dc26
---
NodeJS is only packaged as an ImageStream in Openshift Enterprise 3.9, which is a container image from RH Software Collections. Marking Openshift Enterprise as not affected.
---
This issue has been addressed in the following products:
Red Hat Software Co
Bugzilla
CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [fedora-all]
bugzilla·2018-03-29·CVSS 7.5
CVE-2018-7158 [HIGH] CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [fedora-all]
CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [epel-all]
bugzilla·2018-03-29·CVSS 7.5
CVE-2018-7158 [HIGH] CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [epel-all]
CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
https://access.redhat.com/errata/RHSA-2019:2258https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/https://support.f5.com/csp/article/K27228191?utm_source=f5support&%3Butm_medium=RSShttps://access.redhat.com/errata/RHSA-2019:2258https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/https://support.f5.com/csp/article/K27228191?utm_source=f5support&%3Butm_medium=RSS
2018-05-17
Published