{"id":"CVE-2018-7161","title":"All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH","summary":"All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"nodejs","product":"node.js","affected":["node.js >= 8.0.0, <= 8.8.1","node.js >= 8.9.0, < 8.11.3","node.js >= 9.0.0, < 9.11.2","node.js >= 10.0.0, < 10.4.1"],"patched":["node.js 10.4.1"],"published":"2018-06-13","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:47.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-7161","references":[{"url":"http://www.securityfocus.com/bid/106363","label":"cve-request@iojs.org"},{"url":"https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/","label":"cve-request@iojs.org"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"cve-request@iojs.org"},{"url":"http://www.securityfocus.com/bid/106363","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202003-48","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.07757,"epssPercentile":0.94495,"ingestedAt":"2026-10-08T23:16:47.290Z","slug":"CVE-2018-7161","body":"## Overview\n\nAll versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.\n\n## Affected\n\n- `node.js >= 8.0.0, <= 8.8.1`\n- `node.js >= 8.9.0, < 8.11.3`\n- `node.js >= 9.0.0, < 9.11.2`\n- `node.js >= 10.0.0, < 10.4.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node.js 10.4.1`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.6,"exploitation":0,"ransomware":0},"changes":[]}