CVE-2021-22960

6.5MEDIUM

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

Publicado: 11/3/2021Actualizado: 11/21/2024

Descripción

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

Análisis IAImpulsado por IA

Productos Afectados

llhttpllhttp
llhttpllhttp
oraclegraalvm
20.3.4
oraclegraalvm
21.3.0
debiandebian_linux
11.0

Referencias