CVE-2021-22959

6.5MEDIUM

The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.

发布于: 11/15/2021更新于: 11/21/2024

描述

The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.

AI分析AI驱动

受影响产品

llhttpllhttp
llhttpllhttp
oraclegraalvm
20.3.4
oraclegraalvm
21.3.0
debiandebian_linux
11.0

参考资料