Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3886-1 | nodejs security update |
Debian DSA |
DSA-5991-1 | nodejs security update |
EUVD |
EUVD-2024-25156 | The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first. |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 19 Apr 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-11-04T22:06:04.271Z
Reserved: 2024-02-29T01:04:06.640Z
Link: CVE-2024-27982
Updated: 2025-11-04T22:06:04.271Z
Status : Deferred
Published: 2024-05-07T17:15:07.663
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-27982
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD