CVE-2026-58044: CWE-444 HTTP Request Smuggling in nodejs node
CVE-2026-58044 is a low severity vulnerability in Node.js HTTP client affecting supported release lines 22, 24, and 26. It involves HTTP request smuggling due to request desynchronization in forwarding proxies that rebuild outbound headers from visible IncomingMessage headers while reusing backend connections. The flaw allows certain headers, including Content-Length, to be omitted from userland header objects but still used internally for HTTP framing, potentially causing inconsistencies.
AI Analysis
Technical Summary
This vulnerability arises from Node.js HTTP client behavior where headers beyond configured limits (maxHeadersCount / maxHeaderPairs) are omitted from user-accessible header objects (req.headers, req.rawHeaders, req.headersDistinct) but remain internally used for HTTP message framing. This discrepancy can cause request desynchronization in Node.js-based forwarding proxies that reconstruct outbound headers from visible headers while piping the original body to reused backend connections. The issue affects all supported Node.js release lines: 22, 24, and 26, including specific versions 22.23.1, 24.18.0, and 26.5.0.
Potential Impact
The vulnerability can lead to HTTP request smuggling attacks by causing desynchronization between the headers visible to userland code and those used internally for HTTP framing. This may allow an attacker to manipulate HTTP requests in forwarding proxy scenarios, potentially leading to limited integrity impacts. The CVSS score of 3.7 reflects a low severity with no confidentiality or availability impact and requires network attack vector with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is indicated in the provided data. Users should monitor Node.js vendor advisories for updates and consider limiting maxHeadersCount / maxHeaderPairs settings or avoid reusing backend connections in forwarding proxies until a fix is available.
CVE-2026-58044: CWE-444 HTTP Request Smuggling in nodejs node
Description
CVE-2026-58044 is a low severity vulnerability in Node.js HTTP client affecting supported release lines 22, 24, and 26. It involves HTTP request smuggling due to request desynchronization in forwarding proxies that rebuild outbound headers from visible IncomingMessage headers while reusing backend connections. The flaw allows certain headers, including Content-Length, to be omitted from userland header objects but still used internally for HTTP framing, potentially causing inconsistencies.
CVSS v3.0
Score 3.7low
Affected software
nodejs
node
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from Node.js HTTP client behavior where headers beyond configured limits (maxHeadersCount / maxHeaderPairs) are omitted from user-accessible header objects (req.headers, req.rawHeaders, req.headersDistinct) but remain internally used for HTTP message framing. This discrepancy can cause request desynchronization in Node.js-based forwarding proxies that reconstruct outbound headers from visible headers while piping the original body to reused backend connections. The issue affects all supported Node.js release lines: 22, 24, and 26, including specific versions 22.23.1, 24.18.0, and 26.5.0.
Potential Impact
The vulnerability can lead to HTTP request smuggling attacks by causing desynchronization between the headers visible to userland code and those used internally for HTTP framing. This may allow an attacker to manipulate HTTP requests in forwarding proxy scenarios, potentially leading to limited integrity impacts. The CVSS score of 3.7 reflects a low severity with no confidentiality or availability impact and requires network attack vector with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is indicated in the provided data. Users should monitor Node.js vendor advisories for updates and consider limiting maxHeadersCount / maxHeaderPairs settings or avoid reusing backend connections in forwarding proxies until a fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2026-06-27T15:00:00.780Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6a713a63bf32cb7a3480a4d8
Added to database: 08/04/2026, 01:03:31 UTC
Last enriched: 08/11/2026, 18:28:08 UTC
Last updated: 09/17/2026, 22:09:21 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.