Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nodejs | Jul 30, 2024 | Jun 13, 2018 |
| Freebsd | — | Upgrade node8Upgrade node6Upgrade node | Jun 16, 2018 | Jun 15, 2018 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | Mar 23, 2020 | Jun 13, 2018 |
| Suse | — | Upgrade nodejs10Upgrade nodejs10-docsUpgrade nodejs10-develUpgrade npm10 | Feb 4, 2022 | Jun 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub