Executive brief
The llhttp HTTP parser, used in Node.js, does not strictly enforce the CRLF (carriage return + line feed) delimiter required by HTTP specifications. An attacker can exploit this by using a single CR character to delimit headers, leading to HTTP request smuggling attacks where malicious requests are misinterpreted by proxies or servers, potentially bypassing security controls and enabling cache poisoning or request hijacking.
Technical details
The vulnerability is a protocol compliance flaw in the llhttp parser's HTTP header field delimiter validation. The parser accepts a single CR character as a valid header delimiter instead of strictly requiring CRLF as specified in RFC 7230 Section 3. This allows an attacker to craft malformed HTTP requests that may be interpreted differently by proxies, caches, or backend servers, enabling HTTP request smuggling attacks. No authentication or user interaction is required; the attack is triggered by sending a specially crafted HTTP request over the network. An attacker can exploit this to inject unauthorized requests, bypass security filters, or poison web caches. The vulnerability was fixed in llhttp v8.1.1.
Affected products
- nodejs llhttp before 8.1.1
- nodejs Node.js v16, v18, v20
Timeline
- 2023-07-01: disclosed: Vulnerability published
- 2023-07-01: patched: llhttp v8.1.1 released with fix