Skip to content

Opening book details…

Can I read Node.js HTTP Parser Vulnerability Alert on EtoBox?

Node.js HTTP Parser Vulnerability Alert by Diego Fernando Alvarez Arias is a document available to read on EtoBox.

What is Node.js HTTP Parser Vulnerability Alert about?

The http_parser library used in various versions of Node.js is vulnerable to HTTP desync attacks because it does not properly handle requests that contain both a Transfer-Encoding header and a Content-Length header, as required by RFC 7320. This allows attackers to perform request smuggling and response splitting to hijack sessions, poison cookies, perform clickjacking, and other attacks. The document proposes a patch to http_parser version 2.8.0 to address this issue by returning a 400 response any time bo

Author
Diego Fernando Alvarez Arias
Language
EN