CVE-2018-12116 PUBLISHED

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.

EPSS 0.62% · 69.8th percentile

Risk Scores

EPSS Score
0.62%
69.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSnodejs0, 6.11.4~dfsg-1ubuntu1, 6.11.4~dfsg-1ubuntu2

Timeline

References

Open in Interactive Console →