VDB
DEBIAN-CVE-2016-5325
DEBIAN-CVE-2016-5325
PUBLISHED
CVSS 6.099999904632568 MEDIUM
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Risk Scores
CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | nodejs | 0, 0, 0 |
| Debian:13 | nodejs | 0, 0, 0 |
| Debian:12 | nodejs | 0, 0, 0 |
| Debian:11 | nodejs | 0, 0, 0 |
Timeline
- Oct 10, 2016 CVE Published
- Apr 28, 2026 CVE Updated