Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-8287 Fixed in node, but not in llhttp #88

Closed
jellelicht opened this issue Feb 16, 2021 · 2 comments
Closed

CVE-2020-8287 Fixed in node, but not in llhttp #88

jellelicht opened this issue Feb 16, 2021 · 2 comments

Comments

@jellelicht
Copy link

nodejs/node@051154e addresses CVE-2020-8287 in node, but this package still seems to generate a vulnerable version. Where can this be fixed? Is manually patching the generated .c file the only way to do this for now?

@indutny
Copy link
Member

indutny commented Feb 16, 2021

🤦

Thank you so much for reporting this. The patch was in a lengthy review process and didn't land in this repo in the end. I've released v3.0.1 and v4.0.0 with this fix.

@indutny indutny closed this as completed Feb 16, 2021
@jellelicht
Copy link
Author

@indutny sorry for the ping, but does this also apply to http-parser? Thanks for reacting so fast!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants