HTTP Request Smuggling Affecting nodejs package, versions [22.20.0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-NODEJS-18516684
  • published4 Aug 2026
  • disclosed4 Aug 2026
  • credityushengchen

Introduced: 4 Aug 2026

NewCVE-2026-58044  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to HTTP Request Smuggling in the HTTP client when forwarding proxies rebuild outbound headers from the visible IncomingMessage headers while piping the original body to a reused backend connection. An attacker can manipulate HTTP request headers by sending requests with a large number of headers, causing certain headers such as Content-Length to be omitted from userland while still being used internally for HTTP message framing, potentially leading to request desynchronization.

CVSS Base Scores

version 4.0
version 3.1