CVE-2025-23167
published 2025-05-19CVE-2025-23167: A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables…
PriorityP338medium6.5CVSS 3.0
AVNACLPRNUINSUCLILAN
EPSS
0.47%
37.2th percentile
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | llhttp | < node-undici 7.15.0+dfsg+~cs3.2.0-1 (forky) | node-undici 7.15.0+dfsg+~cs3.2.0-1 (forky) |
| debian | node-undici | < node-undici 7.15.0+dfsg+~cs3.2.0-1 (forky) | node-undici 7.15.0+dfsg+~cs3.2.0-1 (forky) |
| msrc | azl3_fluent-bit_3.1.9-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-13_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_fluent-bit_3.0.6-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nghttp2_1.57.0-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-9_on_cbl_mariner_2.0 | — | — |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 18.0 < 18.* | 18.* |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | 20.0 – 20.19.1 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-23167: A flaw in Node
osv·2025-05-19·CVSS 6.5
CVE-2025-23167 [MEDIUM] CVE-2025-23167: A flaw in Node
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
GHSA
GHSA-hchw-qwx7-4w4c: A flaw in Node
ghsa_unreviewed·2025-05-19
CVE-2025-23167 [MEDIUM] CWE-444 GHSA-hchw-qwx7-4w4c: A flaw in Node
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.
This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact:
* This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
Red Hat
nodejs: Improper HTTP Header Termination in Node.js 20 Enables Request Smuggling
vendor_redhat·2025-05-19·CVSS 6.5
CVE-2025-23167 [MEDIUM] CWE-444 nodejs: Improper HTTP Header Termination in Node.js 20 Enables Request Smuggling
nodejs: Improper HTTP Header Termination in Node.js 20 Enables Request Smuggling
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.
This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact:
* This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
A flaw was found in the HTTP parser of Node.js. This vulnerability allows attackers to perform request smuggling and bypass proxy-based access controls via improperly terminated HTTP/1 headers using \r\n\rX instead of the standard \r\n\r\n.
Mitigati
Microsoft
CVE-2025-23167: FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One
vendor_msrc·2025-05-13·CVSS 6.5
CVE-2025-23167 [MEDIUM] CVE-2025-23167: FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-a
Debian
CVE-2025-23167: llhttp - A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers...
vendor_debian·2025·CVSS 6.5
CVE-2025-23167 [MEDIUM] CVE-2025-23167: llhttp - A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers...
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
Scope: local
forky: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-19
Published