First published: Fri Jun 30 2023(Updated: )
Last updated 24 July 2024
Credit: support@hackerone.com support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/llhttp | <8.1.1 | 8.1.1 |
IBM Cognos Dashboards on Cloud Pak for Data | <=4.7.0 | |
debian/nodejs | <=12.22.12~dfsg-1~deb11u4 | 12.22.12~dfsg-1~deb11u5 18.19.0+dfsg-6~deb12u2 18.19.0+dfsg-6~deb12u1 20.17.0+dfsg-2 |
Node.js | >=16.0.0<16.20.1 | |
Node.js | >=18.0.0<18.16.1 | |
Node.js | >=20.0.0<20.3.1 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Node.js | =16.0.0 | |
Node.js | =18.0.0 | |
Node.js | =20.0.0 | |
Node.js | =20.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30589 is a vulnerability in the llhttp parser in the http module in Node v20.2.0 that can lead to HTTP Request Smuggling (HRS).
CVE-2023-30589 affects Node.js versions 16.0.0, 18.0.0, 20.0.0, and 20.2.0.
CVE-2023-30589 has a severity rating of high.
To fix CVE-2023-30589, update the llhttp package to version 8.1.1 or higher.
You can find more information about CVE-2023-30589 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-30589), [HackerOne](https://hackerone.com/reports/2001873), [GitHub](https://github.com/nodejs/llhttp/releases/tag/release%2Fv8.1.1).