← Back to CVE List
CVE-2022-35256
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt