peter bassill · operator
$ cve CVE-2019-15606 JSON

CVE-2019-15606

9.8
CRITICAL · CVSS 3.1 · EPSS 20% (pctl 97)

Patch early

EPSS 20% — above the 10% action threshold.

Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS20.04% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-02-07
Last modified2026-06-17

Affected (7)

VendorProduct
debiandebian linux
nodejsnode.js
opensuseleap
oraclecommunications cloud native core network function cloud native environment
oraclegraalvm
redhatenterprise linux
redhatenterprise linux eus

References

→ the Explorer  ·  watch your stack  ·  NVD