Malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first. This vulnerability affects all users in all active release lines: 18.x, 20.x and, 21.x. https://nodejs.org/en/blog/vulnerability/april-2024-security-releases
Created nodejs tracking bugs for this issue: Affects: epel-all [bug 2275394] Created nodejs16 tracking bugs for this issue: Affects: fedora-all [bug 2275396] Created nodejs18 tracking bugs for this issue: Affects: fedora-all [bug 2275397] Created nodejs20 tracking bugs for this issue: Affects: fedora-all [bug 2275398] Created nodejs:16-epel/nodejs tracking bugs for this issue: Affects: epel-all [bug 2275395] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-all [bug 2275399]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2779 https://access.redhat.com/errata/RHSA-2024:2779
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:2778 https://access.redhat.com/errata/RHSA-2024:2778
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:2780 https://access.redhat.com/errata/RHSA-2024:2780
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2853 https://access.redhat.com/errata/RHSA-2024:2853
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2910 https://access.redhat.com/errata/RHSA-2024:2910
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:3545 https://access.redhat.com/errata/RHSA-2024:3545
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:4559 https://access.redhat.com/errata/RHSA-2024:4559