Known vulnerabilities in llhttp
Vendor:
Node.js Foundation
Software:
llhttp
Software CPE:
cpe:2.3:a:node_js_foundation:llhttp:*:*:*:*:*:nodejs:*:*
Website:
https://nodejs.org
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
5.3
Breakdown by Severity Chart
9.4.3
9.4.2
9.4.1
9.4.0
9.3.1
9.3.0
9.2.1
8.1.2
6.1.1
9.2.0
6.1.0
9.1.3
9.1.2
9.1.1
9.1.0
9.0.1
9.0.0
8.1.1
6.0.11
8.1.0
8.0.0
7.0.0
6.0.10
2.1.6
2.3.0
6.0.9
6.0.8
6.0.7
2.1.5
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.1.0
5.0.0
4.1.1
4.1.0
4.0.0
3.0.1
3.0.0
2.2.1
2.2.0
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.1
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU88176 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-27982 |
CWE-444 | Medium | 8.1.2 | 05.04.2024 |
SB2024040526 SB2024040851 SB2024040852 and 53 more |
||
| #VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-35256 |
CWE-444 | Medium | 6.0.10 | 03.10.2022 |
SB2022100347 SB2022100401 SB2022100402 and 50 more |
||
| #VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-22960 |
CWE-444 | Medium | 2.1.4, 6.0.6 | 05.01.2022 |
SB2022010523 SB2022010524 SB2022042806 and 40 more |
||
| #VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-22959 |
CWE-444 | Medium | 2.1.4, 6.0.6 | 05.01.2022 |
SB2022010523 SB2022010524 SB2022011841 and 43 more |