CVE-2018-7161High· 7.5▾ TwilightAll versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.8%
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.
node.js >= 8.0.0, <= 8.8.1node.js >= 8.9.0, < 8.11.3node.js >= 9.0.0, < 9.11.2node.js >= 10.0.0, < 10.4.1Upgrade past the affected range:
node.js 10.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2018-7162High· 7.5All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH
CVE-2018-12123Medium· 4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…
CVE-2018-7164High· 7.5Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM
CVE-2018-7167High· 7.5Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service
CVE-2018-12121High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed c…
CVE-2018-12122High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated …