CVE-2018-12116High· 7.5▾ TwilightNode.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will tr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.6%
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the path option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.
node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.15.0node.js >= 8.0.0, <= 8.8.1node.js >= 8.9.0, < 8.14.0suse_enterprise_storage = 4suse_linux_enterprise_server = 12suse_linux_enterprise_server = 15suse_openstack_cloud = 7suse_openstack_cloud = 8Upgrade past the affected range:
node.js 8.14.0Connected by shared product, vendor, weakness, or advisory.
CVE-2018-12123Medium· 4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…
CVE-2018-12121High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed c…
CVE-2018-12122High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated …
CVE-2018-12120High· 8.1Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default
CVE-2018-5407Medium· 4.7Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
CVE-2018-7164High· 7.5Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM