CVE-2023-30589: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
Affected products
- Fedoraproject Fedora: version 37 only; version 38 only
- Node.js Node.js: from 16.0.0, before 16.20.1 (fixed in 16.20.1); from 18.0.0, before 18.16.1 (fixed in 18.16.1); from 20.0.0, before 20.3.1 (fixed in 20.3.1)
Published 2023-07-01. Last modified 2026-10-08.