« List of all CVEs

CVE-2020-8287

Published: 1/6/2021 Last updated: 4/30/2025 Reserved: 1/28/2020

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CNA assigner: hackerone (36234546-b8fa-4601-9d6f-f4e334aa8ea1) Requested by: n/a

Opam packages affected (1)

conf-npm

Products affected (1)

Product Vendor Version
Node NodeJS 23.0 ap381548

References (20)