CVE-2019-15606
CRITICALNodejs Node.js < 10.19.0 - Improper Input Validation
Title source: ruleDescription
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
References (16)
Scores
CVSS v3
9.8
EPSS
0.0134
EPSS Percentile
79.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-20
Status
published
Affected Products (9)
nodejs/node.js
< 10.19.0
nodejs/node.js
< 13.8.0
oracle/communications_cloud_native_core_network_function_cloud_native_environment
oracle/graalvm
oracle/graalvm
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux_eus
opensuse/leap
Timeline
Published
Feb 07, 2020
Tracked Since
Feb 18, 2026