CVE-2018-12116PoC(nodejs / node.js)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-115

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js
  • suse_enterprise_storage
  • suse_linux_enterprise_server
  • suse_openstack_cloud

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
node.jssuse_enterprise_storagesuse_linux_enterprise_serversuse_openstack_cloud

5 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-04: 1Technical Details · 2026-03-04: 103-04
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • dbugs@ptdbugs
    PoC

    👉 Node.js: HTTP Request Splitting protection only works halfway Research by Martino Spagnuolo shows a limitation in the fix for CVE-2018-12116 (HTTP Request Splitting). Node.js validates the HTTP request path for CRLF characters only once — when the request object is created. However, some libraries allow the request path to be modified later through library hooks or middleware, and this change is not revalidated. As a result, an attacker may introduce CRLF sequences after the initial check, potentially leading to HTTP request splitting. Node.js maintainers do not classify this behavior as a vulnerability, but the article provides a detailed analysis and proof-of-concept exploitation. Vulnerable libraries: node-http-proxy, http-proxy-middleware, http-proxy-3 (Vite), httpxy (Nitro/Nuxt), superagent, request, @hapi/wreck 📎 Article: https://r3verii.github.io/cve/2026/02/27/nodejs-toctou.html #dbugs_attacks

    Post summary

    The article exposes a limitation in Node.js’s HTTP request splitting fix, offering a PoC and technical details, while maintainers do not consider it a vulnerability.

    0501341.3K
    551 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---
Appnodejsnode.js---
Appsusesuse_enterprise_storage4--
OSsusesuse_linux_enterprise_server12--
OSsusesuse_linux_enterprise_server15--
OSsusesuse_openstack_cloud7--
OSsusesuse_openstack_cloud8--

Explore more