CVE-2021-22960
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. Th
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
MEDIUM · CVSS 6.5
EPSS 0.00229
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0