A AegiFlow
CRITICALCVSS 9.8

CVE-2019-15606

CVE-2019-15606 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Affected packages

EcosystemPackageAffected versionsFixed versions
Node.jsnode.js[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.