CVE-2016-5325
Moderate
CVE-2016-5325
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Exploit probability
4.1%
Published
October 10, 2016
Required by
Not available
Last source change
July 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
96 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2016-5325
View original source
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html
- http://rhn.redhat.com/errata/RHSA-2017-0002.html
- http://www.securityfocus.com/bid/93483
- https://access.redhat.com/errata/RHSA-2016:2101
- https://github.com/nodejs/node/commit/c0f13e56a20f9bde5a67d873a7f9564487160762
- https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/
- https://security.gentoo.org/glsa/201612-43