A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs20-libs-debuginfoUpgrade nodejs20-debuginfoUpgrade nodejs20-full-i18nUpgrade nodejs20-debugsourceUpgrade nodejs20Upgrade nodejs20-npmUpgrade nodejs20-develUpgrade nodejs20-docsUpgrade v8-11.3-develUpgrade nodejs20-libs | Jun 11, 2025 | May 19, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 19, 2025 |
| Debian | — | No solution exists | May 20, 2025 | May 19, 2025 |
| Redhat_linux | — | Upgrade nodejs-full-i18nUpgrade npmUpgrade nodejs-debuginfoUpgrade nodejs-packaging-bundlerUpgrade nodejs-debugsourceUpgrade nodejs-packagingUpgrade nodejs-develUpgrade nodejs-nodemonUpgrade nodejs-docsUpgrade nodejs | Jun 6, 2025 | May 19, 2025 |
| Rocky_linux | — | Upgrade nodejs-debugsourceUpgrade nodejs-develUpgrade npmUpgrade nodejsUpgrade nodejs-debuginfoUpgrade nodejs-full-i18n | Sep 9, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade nodejs20-develUpgrade nodejs20-docsUpgrade corepack20Upgrade nodejs20Upgrade npm20 | Dec 5, 2025 | Jun 20, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | May 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub