VYPR
Critical severityNVD Advisory· Published Jul 14, 2022· Updated Apr 30, 2025

CVE-2022-32213

CVE-2022-32213

Description

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
llhttpnpm
< 6.0.76.0.7

Affected products

77

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.