cbcvebase.
CVE-2022-32214
published 2022-07-14

CVE-2022-32214: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can…

PriorityP353medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
81.46%
99.6th percentile
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianllhttp< nodejs 18.6.0+dfsg-3 (bookworm)nodejs 18.6.0+dfsg-3 (bookworm)
debiannodejs< nodejs 18.6.0+dfsg-3 (bookworm)nodejs 18.6.0+dfsg-3 (bookworm)
llhttpllhttp< 2.1.52.1.5
llhttpllhttp>= 0 < 6.0.76.0.7
llhttpllhttp>= 6.0.0 < 6.0.76.0.7
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.75.0-1_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrccbl2_nodejs_16.16.0-1_on_cbl_mariner_2.0
msrccm1_nodejs_14.20.0-1_on_cbl_mariner_1.0
nodejsnode>= 10.0 < 10.*10.*
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.*12.*
nodejsnode>= 13.0 < 13.*13.*
nodejsnode>= 14.0 < 14.20.014.20.0
nodejsnode>= 15.0 < 15.*15.*
nodejsnode>= 16.0 < 16.20.016.20.0
nodejsnode>= 17.0 < 17.*17.*
nodejsnode>= 18.0 < 18.5.018.5.0
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*

Detection & IOCsextracted from sources · hover to see the quote

  • HTTP Request Smuggling via non-CRLF header field delimiters — detect HTTP requests where header fields are delimited by characters other than the strict CRLF (\r\n) sequence, which the llhttp parser in Node.js incorrectly accepts
  • Monitor for HTTP Request Smuggling patterns that may result in web cache poisoning or XSS — attacker sends specially crafted HTTP requests smuggling arbitrary HTTP headers
  • ·Affected Node.js release lines are 14.x (below v14.20.1), 16.x (below v16.17.1), and 18.x (below v18.9.1); fixed llhttp library versions are v6.0.7 (for Node.js 18.x) and v2.1.5 (for older lines)
  • ·Red Hat Enterprise Linux 8 nodejs:18 package is marked Not Affected; verify downstream distribution patch status before assuming exposure

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.