HTTP Request Smuggling Affecting llhttp package, versions [0,]
Threat Intelligence
EPSS
1.54% (88th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-LLHTTP-2946425
- published 10 Jul 2022
- disclosed 8 Jul 2022
- credit Zeyu Zhang
Introduced: 8 Jul 2022
CVE-2022-32213 Open this link in a new tabHow to fix?
A fix was pushed into the master
branch but not yet published.
Overview
llhttp is a simple Python wrapper around llhttp, the HTTP parser for Node.js.
Affected versions of this package are vulnerable to HTTP Request Smuggling when the llhttp
parser in the http
module does not correctly parse and validate Transfer-Encoding
headers.
CVSS Scores
version 3.1