{"id":"CVE-2018-12116","title":"Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will tr…","summary":"Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will tr…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-115"],"vendor":"nodejs","product":"node.js","affected":["node.js >= 6.0.0, <= 6.8.1","node.js >= 6.9.0, < 6.15.0","node.js >= 8.0.0, <= 8.8.1","node.js >= 8.9.0, < 8.14.0","suse_enterprise_storage = 4","suse_linux_enterprise_server = 12","suse_linux_enterprise_server = 15","suse_openstack_cloud = 7","suse_openstack_cloud = 8"],"patched":["node.js 8.14.0"],"published":"2018-11-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:44.543","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-12116","references":[{"url":"https://access.redhat.com/errata/RHSA-2019:1821","label":"cve-request@iojs.org"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"cve-request@iojs.org"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"cve-request@iojs.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:1821","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.04574,"epssPercentile":0.91379,"ingestedAt":"2026-10-08T23:16:47.294Z","slug":"CVE-2018-12116","body":"## Overview\n\nNode.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.\n\n## Affected\n\n- `node.js >= 6.0.0, <= 6.8.1`\n- `node.js >= 6.9.0, < 6.15.0`\n- `node.js >= 8.0.0, <= 8.8.1`\n- `node.js >= 8.9.0, < 8.14.0`\n- `suse_enterprise_storage = 4`\n- `suse_linux_enterprise_server = 12`\n- `suse_linux_enterprise_server = 15`\n- `suse_openstack_cloud = 7`\n- `suse_openstack_cloud = 8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node.js 8.14.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.9,"exploitation":0,"ransomware":0},"changes":[]}