CVE-2019-15606

CRITICAL

Nodejs Node.js < 10.19.0 - Improper Input Validation

Title source: rule

Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Scores

CVSS v3 9.8
EPSS 0.0134
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (9)

nodejs/node.js < 10.19.0
nodejs/node.js < 13.8.0
oracle/communications_cloud_native_core_network_function_cloud_native_environment
oracle/graalvm
oracle/graalvm
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux_eus
opensuse/leap

Timeline

Published Feb 07, 2020
Tracked Since Feb 18, 2026