Vulnerability record · CVE-2019-15605 · published 7 February 2020
CVE-2019-15605: Node.js HTTP request smuggling via malformed Transfer-Encoding
Nodejs · Node.Js
Node.js versions 10, 12 and 13 mishandle malformed Transfer-Encoding headers, allowing HTTP request smuggling. This lets an attacker desynchronize front-end and back-end HTTP parsing, so requests can be split or smuggled past intermediaries. It matters because Node.js is widely deployed as an origin or proxy component, and the flaw is remotely reachable without credentials.
Description
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.8) and very high EPSS (99th percentile) on a widely deployed runtime, though not in KEV and requiring a proxy chain to exploit.
What it is
Node.js versions 10, 12 and 13 mishandle malformed Transfer-Encoding headers, allowing HTTP request smuggling. This lets an attacker desynchronize front-end and back-end HTTP parsing, so requests can be split or smuggled past intermediaries. It matters because Node.js is widely deployed as an origin or proxy component, and the flaw is remotely reachable without credentials.
Impact
An attacker can smuggle requests through an intermediary to reach the back-end server, potentially bypassing access controls, poisoning caches, or capturing other users' requests. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via HTTP requests carrying a malformed Transfer-Encoding header; the CVSS vector shows no privileges required and no user interaction. Exploitation depends on a front-end/back-end HTTP chain where parsing differs, which the record does not enumerate.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.57132 (99th percentile), indicating high predicted likelihood of exploitation activity. References are vendor advisories, distro errata and a HackerOne report, with no public exploit tag.
What to do
- Upgrade Node.js to the fixed releases: 10.19.0, 12.15.0 or 13.8.0, or later.
- Apply the linked distro and vendor errata (Red Hat, Debian, Fedora, openSUSE, Oracle, Gentoo, NetApp) for packaged Node.js.
- Normalize and reject ambiguous or malformed Transfer-Encoding and Content-Length headers at the edge proxy.
- Ensure front-end and back-end HTTP parsers agree on request framing; avoid mixing Transfer-Encoding and Content-Length.
- Inventory Node.js instances and embedded runtimes (including GraalVM) to confirm patched versions.
Detection
- Inspect proxy and server logs for requests containing both Transfer-Encoding and Content-Length, or malformed Transfer-Encoding values.
- Alert on HTTP 400/501 responses clustered around header-parsing errors from a single source.
- Compare front-end and back-end request logs for framing mismatches or requests seen by one tier but not the other.
- Monitor for cache poisoning or unexpected response splitting patterns following suspicious header traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-15605 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15605), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.