The parse function in llhttp < 2.1.4 and < 6.0.6. ignores...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 3, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 27, 2023
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
References