← العودة للجدول
CVE-2026-48932
CVE-2026-48932 — A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-
📅 2026-09-01
🟢 Low 🔥 No NVD Vulnerability Vulnerability CVSS 3.7

📋 الوصف الكامل

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection. Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using thos

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-48932

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-48932 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←