Skip to main content

Description

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**

Severity

CVSS 3.0 · CNA7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC · CISA-ADP
Exploitationnone
Automatableyes
Technical impactpartial

Affected Products

VendorProductAffected versions
nodejsnode
20.20.1 to 20.20.1
22.22.1 to 22.22.1
24.14.0 to 24.14.0
25.8.1 to 25.8.1
4.0 to <4.*
5.0 to <5.*
6.0 to <6.*
7.0 to <7.*
8.0 to <8.*
9.0 to <9.*
10.0 to <10.*
11.0 to <11.*
12.0 to <12.*
13.0 to <13.*
14.0 to <14.*
15.0 to <15.*
16.0 to <16.*
17.0 to <17.*
18.0 to <18.*
19.0 to <19.*

References

1 Links

Record Details

Published
2026-03-30
Last updated
2026-07-15
Assigner (CNA)
hackerone
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.