Description
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
References (7)
Scores
CVSS v3
6.1
EPSS
0.0098
EPSS Percentile
76.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-113
Status
published
Products (50)
nodejs/node.js
4.0.0
nodejs/node.js
4.1.0
nodejs/node.js
4.1.1
nodejs/node.js
4.1.2
nodejs/node.js
4.2.0
nodejs/node.js
4.2.1
nodejs/node.js
4.2.2
nodejs/node.js
4.2.3
nodejs/node.js
4.2.4
nodejs/node.js
4.2.5
... and 40 more
Published
Oct 10, 2016
Tracked Since
Feb 18, 2026