Junglewise Threat Intelligence

CVE-2023-30589: llhttp HTTP request smuggling via improper CRLF delimiters

CVE-2023-30589 · Severity: low · CVSS 3.1 · Published 2023-07-01

Technologies: llhttp (npm), Nodejs Node.Js. Vendors: npm, Nodejs.

Executive brief

The llhttp HTTP parser, used in Node.js, does not strictly enforce the CRLF (carriage return + line feed) delimiter required by HTTP specifications. An attacker can exploit this by using a single CR character to delimit headers, leading to HTTP request smuggling attacks where malicious requests are misinterpreted by proxies or servers, potentially bypassing security controls and enabling cache poisoning or request hijacking.

Technical details

The vulnerability is a protocol compliance flaw in the llhttp parser's HTTP header field delimiter validation. The parser accepts a single CR character as a valid header delimiter instead of strictly requiring CRLF as specified in RFC 7230 Section 3. This allows an attacker to craft malformed HTTP requests that may be interpreted differently by proxies, caches, or backend servers, enabling HTTP request smuggling attacks. No authentication or user interaction is required; the attack is triggered by sending a specially crafted HTTP request over the network. An attacker can exploit this to inject unauthorized requests, bypass security filters, or poison web caches. The vulnerability was fixed in llhttp v8.1.1.

Affected products

  • nodejs llhttp before 8.1.1
  • nodejs Node.js v16, v18, v20

Timeline

  • 2023-07-01: disclosed: Vulnerability published
  • 2023-07-01: patched: llhttp v8.1.1 released with fix

References

Related threats