CVE-2016-2216
Last modified
CVE-2016-2216 is a vulnerability of currently unknown severity. The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.. EPSS estimates a 7.01% chance of exploitation in the next 30 days.
Description
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | 0.10.0 |
| Nodejs | Node.Js | 0.10.1 |
| Nodejs | Node.Js | 0.10.2 |
| Nodejs | Node.Js | 0.10.3 |
| Nodejs | Node.Js | 0.10.4 |
| Nodejs | Node.Js | 0.10.5 |
| Nodejs | Node.Js | 0.10.6 |
| Nodejs | Node.Js | 0.10.7 |
| Nodejs | Node.Js | 0.10.8 |
| Nodejs | Node.Js | 0.10.9 |
| Nodejs | Node.Js | 0.10.10 |
| Nodejs | Node.Js | 0.10.11 |
| Nodejs | Node.Js | 0.10.12 |
| Nodejs | Node.Js | 0.10.13 |
| Nodejs | Node.Js | 0.10.14 |
| Nodejs | Node.Js | 0.10.15 |
| Nodejs | Node.Js | 0.10.16 |
| Nodejs | Node.Js | 0.10.16-isaacs-manual |
| Nodejs | Node.Js | 0.10.17 |
| Nodejs | Node.Js | 0.10.18 |
| Nodejs | Node.Js | 0.10.19 |
| Nodejs | Node.Js | 0.10.20 |
| Nodejs | Node.Js | 0.10.21 |
| Nodejs | Node.Js | 0.10.22 |
| Nodejs | Node.Js | 0.10.23 |
| Nodejs | Node.Js | 0.10.24 |
| Nodejs | Node.Js | 0.10.25 |
| Nodejs | Node.Js | 0.10.26 |
| Nodejs | Node.Js | 0.10.27 |
| Nodejs | Node.Js | 0.10.28 |
| Nodejs | Node.Js | 0.10.29 |
| Nodejs | Node.Js | 0.10.30 |
| Nodejs | Node.Js | 0.10.31 |
| Nodejs | Node.Js | 0.10.32 |
| Nodejs | Node.Js | 0.10.33 |
| Nodejs | Node.Js | 0.10.34 |
| Nodejs | Node.Js | 0.10.35 |
| Nodejs | Node.Js | 0.10.36 |
| Nodejs | Node.Js | 0.10.37 |
| Nodejs | Node.Js | 0.10.38 |
| Nodejs | Node.Js | 0.10.39 |
| Nodejs | Node.Js | 0.10.40 |
| Nodejs | Node.Js | 0.10.41 |
| Nodejs | Node.Js | 0.11.6 |
| Nodejs | Node.Js | 0.11.7 |
| Nodejs | Node.Js | 0.11.8 |
| Nodejs | Node.Js | 0.11.9 |
| Nodejs | Node.Js | 0.11.10 |
| Nodejs | Node.Js | 0.11.11 |
| Nodejs | Node.Js | 0.11.12 |
Showing 50 of 85 affected configurations. See NVD for the full list.
References
- https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/Patch, Vendor Advisory
- https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2216?
How severe is CVE-2016-2216?
How do I fix CVE-2016-2216?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-2209Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer en…
- CVE-2016-2210Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer e…
- CVE-2016-2211The AntiVirus Decomposer engine in Symantec Advanced Threat …
- CVE-2016-2212The getOrderByStatusUrlKey function in the Mage_Rss_Helper_O…
- CVE-2016-2213The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.…
- CVE-2016-2214Cross-site scripting (XSS) vulnerability in an unspecified p…
- CVE-2016-2217The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.…
- CVE-2016-2219Cross-site scripting (XSS) vulnerability in the management i…
- CVE-2016-2221Open redirect vulnerability in the wp_validate_redirect func…
- CVE-2016-2222The wp_http_validate_url function in wp-includes/http.php in…
- CVE-2016-2224The __decode_dotted function in libc/inet/resolv.c in uClibc…
- CVE-2016-2225The __read_etc_hosts_r function in libc/inet/resolv.c in uCl…
Are you affected by CVE-2016-2216?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
