CVE-2023-23936: CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
·
Updated

A flaw was found in the fetch API in Node.js that did not prevent CRLF injection in the 'host' header. This issue could allow HTTP response splitting and HTTP header injection.

Other sources

Node.js is vulnerable to CRLF injection, caused by a flaw in the fetch API. By sending a specially-crafted HTTP response containing CRLF character sequences, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning, session hijacking, HTTP response splitting or HTTP header injection.

IBM

The fetch API in Node.js did not prevent CRLF injection in the 'host' header potentially allowing attacks such as HTTP response splitting and HTTP header injection.

Red Hat

Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect host HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the headers.host string before passing to undici.

Affected Software

11 affected componentsFixes available
redhat/nodejs<18-9020020230327152102.rhel9
18-9020020230327152102.rhel9
redhat/nodejs<1:16.19.1-1.el9_2
1:16.19.1-1.el9_2
redhat/nodejs<1:16.20.2-1.el9_0
1:16.20.2-1.el9_0
redhat/Node.js<19.6.1
19.6.1
redhat/Node.js<18.14.1
18.14.1
redhat/Node.js<16.19.1
16.19.1
IBM Cognos Controller<=11.0.0 - 11.0.1
Nodejs Node.js>=16.0.0<16.19.1
Nodejs Node.js>=18.0.0<18.14.1
Nodejs Node.js>=19.0.0<19.6.1
Nodejs Undici Node.js>=2.0.0<5.19.1

Event History

Feb 16, 2023
CVE Published
12:00 AM
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-23936?

CVE-2023-23936 is a vulnerability in the fetch API in Node.js that allows for CRLF injection in the host header.

2

What is the severity of CVE-2023-23936?

CVE-2023-23936 has a severity rating of 6.5 out of 10.

3

How does CVE-2023-23936 affect Node.js?

CVE-2023-23936 affects Node.js versions prior to 19.6.1, 18.14.1, and 16.19.1.

4

How can I fix CVE-2023-23936?

To fix CVE-2023-23936, update Node.js to version 19.6.1, 18.14.1, or 16.19.1.

5

Are there any workarounds for CVE-2023-23936?

As a workaround for CVE-2023-23936, sanitize the `headers.host` string before passing to the affected component.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203