The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: mitre
Published: 2016-04-07T21:00:00
Updated: 2024-08-05T23:24:48.440Z
Reserved: 2016-02-03T00:00:00
Link: CVE-2016-2216

No data.

Status : Deferred
Published: 2016-04-07T21:59:02.790
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2216
