Disclosure summary
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
Source-reported weakness categories
NVD-CWE-Other
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2023-30589
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| nodejs | node.js | * {"versionStartIncluding":"20.0.0","versionEndExcluding":"20.3.1"} |
| fedoraproject | fedora | 37 |
| fedoraproject | fedora | 38 |
Original records & references
- NIST NVD record
- CVE Program record
- hackerone.com — Exploit, Issue Tracking, Third Party Advisory
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Patch, Third Party Advisory
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Patch, Third Party Advisory
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Mailing List
- security.netapp.com — Third Party Advisory
- security.netapp.com
- hackerone.com — Exploit, Issue Tracking, Third Party Advisory
- lists.debian.org
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Patch, Third Party Advisory
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Patch, Third Party Advisory
- lists.fedoraproject.org — Mailing List
- lists.fedoraproject.org — Mailing List
- security.netapp.com — Third Party Advisory
- security.netapp.com
PUBLISHED 2023-06-30T20:15:10-04:00
MODIFIED 2026-10-08T18:17:24-04:00
INGESTED 2026-10-10T20:50:21-04:00