CVE Tools

Llhttp

3 CVEs tracked since 2022. Since Jul 2022, none of them reached CISA KEV.

Llhttp CVEs per month

Jul 2022 to Jul 2022. Point at a month, or focus the strip and use the arrow keys.
Llhttp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0730

Products

The products that kept showing up in Llhttp's monthly top three, with their CVEs summed over those months.

  1. Llhttp31 month

Latest CVEs

The 6 most recently published vulnerabilities affecting Llhttp.

  1. CVE-2022-35256The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.6.5
  2. CVE-2022-32215The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).6.5
  3. CVE-2022-32213The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).6.5
  4. CVE-2022-32214The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).6.5
  5. CVE-2021-22959The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.6.5
  6. CVE-2021-22960The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.6.5

The record

Peak rank
#179 in Jul 2022
Busiest month shown
Jul 2022, 3 CVEs
Months with a KEV entry
0 since Jul 2022
Monthly snapshots
1 since 2022
Llhttp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store