---
id: CVE-2023-30589
title: >-
  The llhttp parser in the http module in Node v20.2.0 does not strictly use the
  CRLF sequence to delimit HTTP requests
summary: "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\r\n\r\nThe CR character (without LF) is sufficient to delimit HTTP header f…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
vendor: nodejs
product: node.js
affected:
  - 'node.js >= 16.0.0, < 16.20.1'
  - 'node.js >= 18.0.0, < 18.16.1'
  - 'node.js >= 20.0.0, < 20.3.1'
  - fedora = 37
  - fedora = 38
patched:
  - node.js 20.3.1
published: '2023-07-01'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:24.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-30589'
references:
  - url: 'https://hackerone.com/reports/2001873'
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IV326O2X4BE3SINX5FJHMAKVHUAA4ZYF/
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCVG4TQRGTK4LKAZKVEQAUEJM7DUACYE/
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEEQIN5242K5NBE2CZ4DYTNA5B4YTYE5/
    label: support@hackerone.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/
    label: support@hackerone.com
  - url: 'https://security.netapp.com/advisory/ntap-20230803-0009/'
    label: support@hackerone.com
  - url: 'https://security.netapp.com/advisory/ntap-20240621-0006/'
    label: support@hackerone.com
  - url: 'https://hackerone.com/reports/2001873'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IV326O2X4BE3SINX5FJHMAKVHUAA4ZYF/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCVG4TQRGTK4LKAZKVEQAUEJM7DUACYE/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEEQIN5242K5NBE2CZ4DYTNA5B4YTYE5/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230803-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20240621-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03906
epssPercentile: 0.90011
ingestedAt: '2026-10-08T23:16:47.350Z'
---

## Overview

The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20

## Affected

- `node.js >= 16.0.0, < 16.20.1`
- `node.js >= 18.0.0, < 18.16.1`
- `node.js >= 20.0.0, < 20.3.1`
- `fedora = 37`
- `fedora = 38`

## Remediation

Upgrade past the affected range:

- `node.js 20.3.1`
