← Back

CVE-2020-8201

nvd nist
Published: Sep 18, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.

Affected (4)

1 product
Node.js
1 product
Leap
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 14.0.0 to 14.11.0
From 12.0.0 to 12.18.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.2
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 33

References (12)

Source: support@hackerone.com
Permissions Required
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.