7.5
CVSSv3

CVE-2018-12122

Published: 28/11/2018 Updated: 06/09/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js

suse suse linux enterprise server 12

suse suse enterprise storage 4

suse suse openstack cloud 7

suse suse openstack cloud 8

suse suse linux enterprise server 15

Vendor Advisories

Synopsis Important: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
Nodejs: All versions prior to Nodejs 6150, 8140, 10140 and 1130: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time ...

Github Repositories

Wrapper for the BPOST's address autosuggest and validate API. Only for Belgium addresses.

# Address autosuggestion and validation Wrapper for the BPOST's address autosuggest and validate API - Only for Belgium addresses - Supports typescript Required Node changes You might need to set up a flag when running your app such as --max-http-header-size 35000 since the incoming headers are way more than default Node's default 8KB is therefor not enough