Unrated severityNVD Advisory· Published Nov 3, 2021· Updated Apr 30, 2025
CVE-2021-22960
CVE-2021-22960
Description
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
Affected products
48- osv-coords46 versionspkg:apk/chainguard/ruby3.2-llhttppkg:apk/chainguard/ruby3.2-llhttp-ffipkg:apk/chainguard/ruby3.2-llhttp-mripkg:apk/wolfi/ruby3.2-llhttppkg:apk/wolfi/ruby3.2-llhttp-ffipkg:apk/wolfi/ruby3.2-llhttp-mripkg:rpm/almalinux/nodejspkg:rpm/almalinux/nodejs-develpkg:rpm/almalinux/nodejs-docspkg:rpm/almalinux/nodejs-full-i18npkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/nodejs-packagingpkg:rpm/almalinux/npmpkg:rpm/opensuse/nodejs10&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/nodejs10&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nodejs12&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/nodejs12&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/nodejs14&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/nodejs14&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/nodejs14&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/nodejs16&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nodejs10&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/nodejs10&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/nodejs10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/nodejs10&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/nodejs10&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/nodejs10&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP2pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP3pkg:rpm/suse/nodejs14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP2pkg:rpm/suse/nodejs14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP3
< 0+ 45 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 1:16.13.1-3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 2.0.15-1.module_el8.6.0+2904+f21ad6f4
- (no CPE)range: < 25-1.module_el8.5.0+246+05401605
- (no CPE)range: < 1:8.1.2-1.16.13.1.3.module_el8.5.0+2605+45d748af
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 12.22.7-lp152.3.21.1
- (no CPE)range: < 12.22.7-4.22.1
- (no CPE)range: < 14.18.1-lp152.17.1
- (no CPE)range: < 14.18.1-15.21.2
- (no CPE)range: < 14.18.1-1.1
- (no CPE)range: < 16.13.0-1.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 10.24.1-150000.1.47.1
- (no CPE)range: < 12.22.9-1.38.1
- (no CPE)range: < 12.22.7-4.22.1
- (no CPE)range: < 12.22.7-4.22.1
- (no CPE)range: < 14.18.1-6.18.2
- (no CPE)range: < 14.18.1-15.21.2
- (no CPE)range: < 14.18.1-15.21.2
Patches
Vulnerability mechanics
References
3- www.debian.org/security/2022/dsa-5170mitrevendor-advisoryx_refsource_DEBIAN
- hackerone.com/reports/1238099mitrex_refsource_MISC
- www.oracle.com/security-alerts/cpujan2022.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.