Llhttp is a minimalist HTTP parser library embedded across Node.js runtime and dependent web frameworks, where its compact footprint belies substantial downstream reach. The vendor's vulnerability profile centers on HTTP request interpretation edge cases, particularly inconsistent parsing that can lead to request smuggling when downstream components apply divergent interpretations, a structural weakness that recurs in HTTP parsing implementations across the ecosystem. Current vulnerability counts and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Llhttp over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32214MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm | Jul 14, 2022 | 6.5 | 67 | NO | NO |
CVE-2022-32215MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smug | Jul 14, 2022 | 6.5 | 52 | NO | NO |
CVE-2022-32213MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smugg | Jul 14, 2022 | 6.5 | 44 | NO | NO |
CVE-2022-35256MEDIUM The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | Dec 5, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-22959MEDIUM The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. | Nov 15, 2021 | 6.5 | 24 | NO | NO |
CVE-2021-22960MEDIUM The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain condi | Nov 3, 2021 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Llhttp.
Media articles that mention a CVE ID that affects a product developed by Llhttp — matched by CVE ID, not by vendor name.