Vulnerabilities
- CVSS
- 3.7 Low
- Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N- Risk score
- 29.6
- Published
- 2026-08-04
- Status
- Received
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.
Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in Node.js, impacting versions 22.x, 24.x, and 26.x prior to the specified release dates. These vulnerabilities can lead to data integrity compromise, data confidentiality is…
Advisories and references