CVE-2018-12122 describes a Slowloris HTTP Denial of Service vulnerability affecting Node.js versions prior to 6.15.0, 8.14.0, 10.14.0, and 11.3.0, impacting various Node.js deployments including those on SUSE platforms. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to exhaust server resources by maintaining slow HTTP/HTTPS connections, leading to a complete denial of service. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for a high impact remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.15.1CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* | ||
>= 8.0.0, < 8.14.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* | ||
>= 10.0.0, < 10.14.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* | ||
>= 11.0.0, < 11.3.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | ||
4CPE matchmatch criteria | cpe:2.3:a:suse:suse_enterprise_storage:4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
nodejs: Slowloris HTTP Denial of Service
Nov 27, 2018Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
Nov 13, 2018