A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection. Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Details
- CVSS 3.0 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nodejsUpgrade nodejs-current | Aug 5, 2026 | Aug 4, 2026 |
| Amazon_linux_2023 | — | Upgrade nodejs22-libs-debuginfoUpgrade nodejs24-full-i18nUpgrade nodejs24-debuginfoUpgrade nodejs24Upgrade nodejs22-full-i18nUpgrade v8-12.4-develUpgrade nodejs22-npmUpgrade nodejs24-libs-debuginfoUpgrade nodejs22-debuginfoUpgrade nodejs22Upgrade nodejs22-libsUpgrade nodejs24-libsUpgrade nodejs24-debugsourceUpgrade nodejs22-develUpgrade nodejs22-debugsourceUpgrade v8-13.6-develUpgrade nodejs22-docsUpgrade nodejs24-npmUpgrade nodejs24-develUpgrade nodejs24-docs | Aug 18, 2026 | Aug 4, 2026 |
| Redhat_linux | — | No solution exists | Aug 12, 2026 | Aug 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 12, 2026 | Aug 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub