{"id":"CVE-2017-14919","title":"Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBit…","summary":"Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBit…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"nodejs","product":"node.js","affected":["node.js = 4.8.2","node.js = 4.8.3","node.js = 4.8.4","node.js = 6.10.2","node.js = 6.10.3","node.js = 6.11.0","node.js = 6.11.1","node.js = 6.11.2","node.js = 6.11.3","node.js = 6.11.4","node.js = 8.0.0","node.js = 8.1.0","node.js = 8.1.1","node.js = 8.1.2","node.js = 8.1.3","node.js = 8.1.4","node.js = 8.2.0","node.js = 8.2.1","node.js = 8.3.0","node.js = 8.4.0","node.js = 8.5.0","node.js = 8.6.0","node.js = 8.7.0"],"published":"2017-10-30","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2017-14919","references":[{"url":"http://www.securityfocus.com/bid/101881","label":"cve@mitre.org"},{"url":"https://nodejs.org/en/blog/release/v4.8.5/","label":"cve@mitre.org"},{"url":"https://nodejs.org/en/blog/release/v6.11.5/","label":"cve@mitre.org"},{"url":"https://nodejs.org/en/blog/release/v8.8.0/","label":"cve@mitre.org"},{"url":"https://nodejs.org/en/blog/vulnerability/oct-2017-dos/","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/101881","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/release/v4.8.5/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/release/v6.11.5/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/release/v8.8.0/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/oct-2017-dos/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-470355.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.07752,"epssPercentile":0.94454,"ingestedAt":"2026-07-14T12:36:47.616Z","slug":"CVE-2017-14919","body":"## Overview\n\nNode.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.\n\n## Affected\n\n- `node.js = 4.8.2`\n- `node.js = 4.8.3`\n- `node.js = 4.8.4`\n- `node.js = 6.10.2`\n- `node.js = 6.10.3`\n- `node.js = 6.11.0`\n- `node.js = 6.11.1`\n- `node.js = 6.11.2`\n- `node.js = 6.11.3`\n- `node.js = 6.11.4`\n- `node.js = 8.0.0`\n- `node.js = 8.1.0`\n- `node.js = 8.1.1`\n- `node.js = 8.1.2`\n- `node.js = 8.1.3`\n- `node.js = 8.1.4`\n- `node.js = 8.2.0`\n- `node.js = 8.2.1`\n- `node.js = 8.3.0`\n- `node.js = 8.4.0`\n- `node.js = 8.5.0`\n- `node.js = 8.6.0`\n- `node.js = 8.7.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.6,"exploitation":0,"ransomware":0},"changes":[]}