NodeJS is vulnerable to HTTP request smuggling
65
Medium Risk
NodeJS' HTTP server is vulnerable to HTTP request smuggling via content length obfuscation.
You're affected if you are running any Express or HTTP server from Node 18 to 21.
NodeJS is vulnerable to HTTP request smuggling.
To fix the vulnerability upgrade NodeJS to the latest April 2024 security upgrades
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant