A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade v8-11.3-develUpgrade nodejs20-libsUpgrade nodejs20-full-i18nUpgrade nodejs20Upgrade nodejs20-libs-debuginfoUpgrade nodejs20-debugsourceUpgrade nodejs20-debuginfoUpgrade nodejs20-develUpgrade nodejs20-docsUpgrade nodejs20-npm | Jun 11, 2025 | May 19, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 19, 2025 |
| Debian | — | No solution exists | May 20, 2025 | May 19, 2025 |
| Redhat_linux | — | Upgrade nodejs-debuginfoUpgrade npmUpgrade nodejs-packaging-bundlerUpgrade nodejs-full-i18nUpgrade nodejs-packagingUpgrade nodejs-nodemonUpgrade nodejs-docsUpgrade nodejsUpgrade nodejs-debugsourceUpgrade nodejs-devel | Jun 6, 2025 | May 19, 2025 |
| Rocky_linux | — | Upgrade nodejs-debuginfoUpgrade npmUpgrade nodejsUpgrade nodejs-full-i18nUpgrade nodejs-debugsourceUpgrade nodejs-devel | Sep 9, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade corepack20Upgrade nodejs20-docsUpgrade nodejs20Upgrade npm20Upgrade nodejs20-devel | Dec 5, 2025 | Jun 20, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | May 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub