VYPR
Critical severityNVD Advisory· Published Jul 14, 2022· Updated Apr 30, 2025

CVE-2022-32214

CVE-2022-32214

Description

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
llhttpnpm
< 6.0.76.0.7

Affected products

74

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.