← Back to CVE List

CVE-2024-27982

Published: 2024-05-07T17:15Z
Last Modified: 2025-03-28T21:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt