Intel

CVE-2024-27982

NodeJS is vulnerable to HTTP request smuggling

HTTP request smuggling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 7, 2024

65

Medium Risk

This Affects:

NodeJS
Are you affected? Scan for Free

TL;DR

NodeJS' HTTP server is vulnerable to HTTP request smuggling via content length obfuscation.

Who does this affect?

You're affected if you are running any Express or HTTP server from Node 18 to 21.

Background info

NodeJS is vulnerable to HTTP request smuggling.

How to fix this

To fix the vulnerability upgrade NodeJS to the latest April 2024 security upgrades