« List of all CVEs

CVE-2019-15606

Published: 2/7/2020 Last updated: 4/30/2025 Reserved: 8/26/2019

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CNA assigner: hackerone (36234546-b8fa-4601-9d6f-f4e334aa8ea1) Requested by: n/a

Opam packages affected (1)

conf-npm

Products affected (1)

Product Vendor Version
Node NodeJS 6.0.2

References (32)