cbcvebase.
CVE-2019-15605
published 2020-02-07

CVE-2019-15605: HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
57.13%
99.0th percentile
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianhttp-parser< http-parser 2.9.4-2 (bookworm)http-parser 2.9.4-2 (bookworm)
debiannodejs< http-parser 2.9.4-2 (bookworm)http-parser 2.9.4-2 (bookworm)
fedoraprojectfedora
github.comapple_swift-nio>= 1.0.0 < 1.14.21.14.2
github.comapple_swift-nio>= 2.0.0 < 2.13.12.13.1
nodejsnode>= 10.0 < 10.19.010.19.0
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.15.012.15.0
nodejsnode>= 13.0 < 13.8.013.8.0
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 10.0.0 < 10.19.010.19.0
nodejsnode.js>= 12.0.0 < 12.15.012.15.0
nodejsnode.js>= 13.0.0 < 13.8.013.8.0
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-3ubuntu1.110.19.0~dfsg-3ubuntu1.1
nodejsnodejs>= 0 < 4.2.6~dfsg-1ubuntu4.2+esm24.2.6~dfsg-1ubuntu4.2+esm2

Detection & IOCsextracted from sources · hover to see the quote

  • The attack vector is a specially crafted HTTP request with a malformed Transfer-Encoding header, enabling HTTP request smuggling / desync attacks against Node.js servers deployed behind a proxy that reuses connections.
  • Monitor for HTTP requests containing malformed or obfuscated Transfer-Encoding headers (e.g., with whitespace, unusual casing, or extra characters) targeting Node.js HTTP servers, which is the root trigger for this smuggling vulnerability.
  • Payloads crafted via this smuggling flaw can be used to hijack user sessions, poison cookies, and perform clickjacking — monitor for unexpected session/cookie manipulation in responses proxied through Node.js.
  • ·Vulnerability exists in Node.js versions 10, 12, and 13 specifically; fixed in Node.js v10.19.0, v12.15.0, and v13.8.0. Verify the deployed Node.js version before applying detection logic.
  • ·The underlying parser fix is in http-parser (C library) at the referenced commit; the fix is also present in http-parser-js 2.9.3+. Environments using the C http-parser library separately (e.g., Fedora/RHEL packages) must patch that component independently.
  • ·Red Hat Quay 3 is explicitly listed as NOT affected by this CVE.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.