A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs20Upgrade nodejs20-libs-debuginfoUpgrade nodejs20-full-i18nUpgrade nodejs20-debuginfoUpgrade nodejs20-develUpgrade nodejs20-debugsourceUpgrade nodejs20-npmUpgrade nodejs20-docsUpgrade nodejs20-libsUpgrade v8-11.3-devel | Jun 11, 2025 | May 19, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 19, 2025 |
| Debian | — | No solution exists | May 20, 2025 | May 19, 2025 |
| Redhat_linux | — | Upgrade nodejs-packaging-bundlerUpgrade nodejs-full-i18nUpgrade npmUpgrade nodejs-debuginfoUpgrade nodejs-packagingUpgrade nodejsUpgrade nodejs-develUpgrade nodejs-debugsourceUpgrade nodejs-nodemonUpgrade nodejs-docs | Jun 6, 2025 | May 19, 2025 |
| Rocky_linux | — | Upgrade nodejs-debugsourceUpgrade nodejs-develUpgrade nodejs-full-i18nUpgrade nodejsUpgrade nodejs-debuginfoUpgrade npm | Sep 9, 2025 | Jul 29, 2025 |
| Suse | — | Upgrade nodejs20-develUpgrade corepack20Upgrade nodejs20-docsUpgrade npm20Upgrade nodejs20 | Dec 5, 2025 | Jun 20, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | May 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub