References https://nodejs.org/en/blog/vulnerability/july-2022-security-releases https://github.com/advisories/GHSA-5689-v88g-g6rv https://hackerone.com/reports/1524555 https://hackerone.com/reports/1501679 https://zeropath.com/blog/cve-2022-35256-nodejs-http-request-smuggling https://www.tenablecloud.cn/plugins/nessus/165633 https://www.sentinelone.com/vulnerability-database/cve-2022-32213/ https://research.jfrog.com/vulnerabilities/nodejs-http-smuggling-xray-231662/ https://app.opencve.io/cve/?vendor=llhttp https://www.tenablecloud.cn/plugins/nessus/165634 https://niubl.github.io/2021/05/02/http-request-smuggling-in-nodejs/ https://hackerone.com/reports/1665156
Related VulnerabilitiesPoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCEFlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)Evertz SDVN /v.1.5/php/features/feature-transfer-export.php 命令执行漏洞(CVE-2025-4009)Drupal core /jsonapi/node/article SQL 注入漏洞(CVE-2026-9082)PoCNode-RED /auth/token 默认口令漏洞Vite Dev Server /node_modules/.vite/deps 文件读取漏洞 (CVE-2026-39365)PoCnode-red-unauth: Node-RED - Unauthenticated AccessNocoBase /api/flow_nodes:test 代码执行漏洞(CVE-2026-34156)天锐绿盘云文档安全管理平台/lddsm/service/../ldfbsnodeDocumentController/restorMachineToClient.do 命令执行漏洞PoCCVE-2023-35708: MOVEit Transfer - SQL InjectionNode-Tar Node-Tar 未授权 路径遍历漏洞ComfyUI /api/customnode/install/git_url 代码执行漏洞(CVE-2025-67303)