cbcvebase.
CVE-2019-15606
published 2020-02-07

CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
20.04%
97.1th percentile
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiannodejs< nodejs 10.19.0~dfsg-1 (bookworm)nodejs 10.19.0~dfsg-1 (bookworm)
nodejsnode>= 10.0 < 10.19.010.19.0
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.15.012.15.0
nodejsnode>= 13.0 < 13.8.013.8.0
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 10.0.0 < 10.19.010.19.0
nodejsnode.js>= 12.0.0 < 12.15.012.15.0
nodejsnode.js>= 13.0.0 < 13.8.013.8.0
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-3ubuntu1.110.19.0~dfsg-3ubuntu1.1
nodejsnodejs>= 0 < 4.2.6~dfsg-1ubuntu4.2+esm24.2.6~dfsg-1ubuntu4.2+esm2
nodejsnodejs>= 0 < 8.10.0~dfsg-2ubuntu0.4+esm28.10.0~dfsg-2ubuntu0.4+esm2
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclegraalvm

Detection & IOCsextracted from sources · hover to see the quote

  • HTTP header values containing trailing whitespace may be used to bypass authorization checks in Node.js — inspect incoming HTTP requests for header values with trailing optional whitespace (spaces/tabs) that could differ from what a Node.js server sees vs. an upstream proxy
  • Look for HTTP(s) requests where header values include trailing whitespace that passes upstream proxy validation but is not stripped by the Node.js HTTP(s) server, enabling authorization bypass
  • ·Vulnerability affects Node.js versions 10, 12, and 13 only; fixed in 10.19.0, 12.15.0, and 13.8.0 — verify Node.js version before applying detection logic
  • ·Red Hat Quay 3 nodejs package is listed as Not Affected — scope detection efforts to confirmed affected Node.js deployments
  • ·The upstream HackerOne report detailing the exact exploitation technique is not yet public — full attack surface details may be incomplete

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.