CVE-2012-2330: Node.js
Medium severity, CVSS 6.4. EPSS: 2.6% chance of exploitation in the next 30 days.
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
Affected products
- Node.js Node.js: up to and including 0.6.16; version 0.7.0 only; version 0.7.1 only; version 0.7.2 only; version 0.7.3 only; version 0.7.4 only; …
Published 2012-08-13. Last modified 2026-06-16.