TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Node.js HTTP Request Smuggling via Empty Headers Separated by CR

20 pointsby osivertssonalmost 2 years ago

1 comment

bkallusalmost 2 years ago
Dang; I found and reported this vulnerability on June 5 (after this report was made, but before it was made public or patched), and was told that they were already aware of the bug and working on a fix. I didn&#x27;t realize I&#x27;d been beaten by only 10 days!<p><a href="https:&#x2F;&#x2F;github.com&#x2F;aio-libs&#x2F;aiohttp&#x2F;issues&#x2F;7312">https:&#x2F;&#x2F;github.com&#x2F;aio-libs&#x2F;aiohttp&#x2F;issues&#x2F;7312</a> <a href="https:&#x2F;&#x2F;github.com&#x2F;nodejs&#x2F;premature-disclosures&#x2F;issues&#x2F;4">https:&#x2F;&#x2F;github.com&#x2F;nodejs&#x2F;premature-disclosures&#x2F;issues&#x2F;4</a>
评论 #36587825 未加载