CVE-2022-35256
Summary
| CVE | CVE-2022-35256 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-05 22:15:00 UTC |
| Updated | 2023-05-12 13:30:00 UTC |
| Description | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160143 Oracle Enterprise Linux Security Update for nodejs (ELSA-2022-6963)
- 160144 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2022-6964)
- 160211 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2022-7821)
- 160231 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2022-7830)
- 160410 Oracle Enterprise Linux Security Update for nodejs and nodejs-nodemon (ELSA-2023-0321)
- 181502 Debian Security Update for nodejs (DSA 5326-1)
- 182159 Debian Security Update for nodejs (CVE-2022-35256)
- 199926 Ubuntu Security Notification for Node.js Vulnerabilities (USN-6491-1)
- 240731 Red Hat Update for nodejs:16 (RHSA-2022:6964)
- 240732 Red Hat Update for nodejs (RHSA-2022:6963)
- 240747 Red Hat Update for rh-nodejs14-nodejs (RHSA-2022:7044)
- 240851 Red Hat Update for nodejs:14 (RHSA-2022:7830)
- 240857 Red Hat Update for nodejs:18 (RHSA-2022:7821)
- 241117 Red Hat Update for nodejs and nodejs-nodemon security (RHSA-2023:0321)
- 241304 Red Hat Update for nodejs:14 security (RHSA-2023:1533)
- 241341 Red Hat Update for nodejs:14 security (RHSA-2023:1742)
- 283356 Fedora Security Update for nodejs (FEDORA-2022-de515f765f)
- 283357 Fedora Security Update for nodejs (FEDORA-2022-52dec6351a)
- 283432 Fedora Security Update for nodejs (FEDORA-2022-1667f7b60a)
- 296098 Oracle Solaris 11.4 Support Repository Update (SRU) 52.132.2 Missing (CPUOCT2022)
- 355273 Amazon Linux Security Advisory for nodejs : ALAS2023-2023-084
- 502514 Alpine Linux Security Update for nodejs-current
- 502530 Alpine Linux Security Update for nodejs
- 502531 Alpine Linux Security Update for nodejs
- 504211 Alpine Linux Security Update for nodejs
- 753199 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2022:3656-1)
- 753342 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2022:3616-1)
- 753404 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2022:3615-1)
- 753490 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2022:3614-1)
- 753698 SUSE Enterprise Linux Security Update for nodejs18 (SUSE-SU-2023:0419-1)
- 904629 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (11578)
- 904753 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (11578-1)
- 940692 AlmaLinux Security Update for nodejs (ALSA-2022:6963)
- 940721 AlmaLinux Security Update for nodejs:16 (ALSA-2022:6964)
- 940740 AlmaLinux Security Update for nodejs:18 (ALSA-2022:7821)
- 940775 AlmaLinux Security Update for nodejs:14 (ALSA-2022:7830)
- 940906 AlmaLinux Security Update for nodejs and nodejs-nodemon (ALSA-2023:0321)
- 960403 Rocky Linux Security Update for nodejs:16 (RLSA-2022:6964)
- 960479 Rocky Linux Security Update for nodejs:18 (RLSA-2022:7821)
- 960517 Rocky Linux Security Update for nodejs and nodejs-nodemon (RLSA-2023:0321)
- 960543 Rocky Linux Security Update for nodejs (RLSA-2022:6963)
- 960636 Rocky Linux Security Update for nodejs:14 (RLSA-2022:7830)