Unrated severityNVD Advisory· Published Nov 15, 2021· Updated Apr 30, 2025
CVE-2021-22959
CVE-2021-22959
Description
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.debian.org/security/2022/dsa-5170mitrevendor-advisoryx_refsource_DEBIAN
- hackerone.com/reports/1238709mitrex_refsource_MISC
- www.oracle.com/security-alerts/cpujan2022.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.