Web Hack List

Later archive addition

Node.JS Request Smuggling

The article demonstrates request smuggling through Node.js's HTTP client by placing control characters and tab-separated request lines in an attacker-controlled path. It explains downstream parser requirements, keep-alive session risks, a hotpatch, and the upstream fix.

Record

Researcher
Chris Tarquini

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Chris Tarquini, first published at the original source. Preserved copies are kept so the citation survives its host.