CVE-2018-7160High· 8.8▾ TwilightThe Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or anoth…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Oct 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.9%
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.
node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.14.0node.js >= 8.0.0, <= 8.8.1node.js >= 8.9.0, < 8.11.0node.js >= 9.0.0, < 9.10.0Upgrade past the affected range:
node.js 9.10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2018-7159Medium· 5.3The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`
CVE-2018-7161High· 7.5All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH
CVE-2018-7158High· 7.5The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector
CVE-2018-7167High· 7.5Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service
CVE-2018-7162High· 7.5All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH
CVE-2021-44533Medium· 5.3Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly