debian · CVE-2025-23167

Quick triage

Priority: unimportant Published: Updated: Thu, 23 Jul 2026 01:18:52 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-23167 unimportant priority: Debian including 2 source packages (llhttp, node-undici), 6 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 4, open 2.

Description:

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

cvelogic Threat Intelligence