CVE-2017-16026 describes a vulnerability in the Request HTTP client (versions >=2.2.6 <2.47.0 and >2.51.0 <=2.67.0) where providing a number as the body type for a multipart request can lead to the transmission of uninitialized memory. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high confidentiality impact, allowing an attacker to potentially leak sensitive data without user interaction. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.6, < 2.47.0CPE matchmatch criteria | cpe:2.3:a:request_project:request:*:*:*:*:*:node.js:*:* | ||
> 2.51.0, <= 2.67.0CPE matchmatch criteria | cpe:2.3:a:request_project:request:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.