Hide Forgot
The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. The fix for this is included in llhttp v2.1.4 and v6.0.6. Impacts: All versions of the 16.x, 14.x, and 12.x releases lines.
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014066]
Created nodejs tracking bugs for this issue: Affects: epel-all [bug 2014109] Created nodejs:10/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014110] Created nodejs:12/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014111] Created nodejs:13/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014112] Created nodejs:14/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014113] Created nodejs:15/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014114] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2014115]
HackerOne report (currently private) : https://hackerone.com/reports/1238709
Upstream fixes for Node.JS : node 12 : https://github.com/nodejs/node/commit/21a2e554e3eaa325abbdb28f366928d0ccc0a0f0 node 14 : https://github.com/nodejs/node/commit/8c254ca7e4693fb778d808fa835b095de6c9fdd4 node 16 : https://github.com/nodejs/node/commit/af488f8dc82d69847992ea1cd2f53dc8082b3b91 Upstream fixes for llhttp : v.6 : https://github.com/nodejs/llhttp/commit/b069a2ba7d6caada9b1a1d99a511ce4631b02ed1 v.2.1.x : https://github.com/nodejs/llhttp/commit/a835370c29ce7c793bd2cb40cacf626d18669371
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:5171 https://access.redhat.com/errata/RHSA-2021:5171
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:0041 https://access.redhat.com/errata/RHSA-2022:0041
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Extended Update Support Via RHSA-2022:0246 https://access.redhat.com/errata/RHSA-2022:0246
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:0350 https://access.redhat.com/errata/RHSA-2022:0350
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-22960
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:4914 https://access.redhat.com/errata/RHSA-2022:4914