CVE-2018-7164

🟡 Monitoruj

Błąd w Node.js powoduje wzrost zużycia pamięci, co może prowadzić do odmowy usługi.

CVSS
7.5
EPSS
6.4%
Exploit
none
Vendor
nodejs
Opis źródłowy (NVD)

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)6.4%
Opublikowano (NVD)2018-06-13 16:29:01 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:48 UTC
Referencje