HTTP Request Smuggling Affecting node package, versions [22.0.0, 22.23.2)[24.0.0, 24.18.1)[26.0.0, 26.5.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UPSTREAM-NODE-18553664
  • published6 Aug 2026
  • disclosed4 Aug 2026
  • credityushengchen

Introduced: 4 Aug 2026

NewCVE-2026-58044  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade node to version 22.23.2, 24.18.1, 26.5.1 or higher.

Overview

node is a JavaScript runtime built on Chrome's V8 JavaScript engine.

Affected versions of this package are vulnerable to HTTP Request Smuggling in the HTTP client when forwarding proxies rebuild outbound headers from the visible IncomingMessage headers while piping the original body to a reused backend connection. An attacker can manipulate HTTP request headers by sending requests with a large number of headers, causing certain headers such as Content-Length to be omitted from userland while still being used internally for HTTP message framing, potentially leading to request desynchronization.

CVSS Base Scores

version 4.0
version 3.1