Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nodejs | Jul 30, 2024 | Mar 28, 2019 |
| Freebsd | — | Upgrade nodeUpgrade node6Upgrade node8Upgrade node10 | Mar 3, 2019 | Mar 3, 2019 |
| Gentoo Linux | — | Upgrade net-libs/nodejs. | Mar 23, 2020 | Mar 28, 2019 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-8 to version 8.17.0-11.4.21.0.1.69.0 on Solaris 11.4 | Jan 19, 2021 | Mar 28, 2019 |
| Suse | — | Upgrade nodejs4-develUpgrade npm4Upgrade nodejs6Upgrade nodejs6-docsUpgrade nodejs6-develUpgrade nodejs4Upgrade nodejs4-docsUpgrade npm6 | Apr 1, 2019 | Feb 28, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub