Ecstatic Project maintains a focused HTTP static-file-serving library whose niche role belies its presence in web application stacks and development tooling. Its observed vulnerability pattern centers on input-validation and resource-consumption weaknesses, typical of parser-oriented components handling untrusted request data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecstatic Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10703HIGH A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and c | Dec 14, 2017 | 7.5 | 26 | NO | NO |
CVE-2019-10775HIGH ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application. | Jan 2, 2020 | 7.5 | 24 | NO | NO |
CVE-2015-9242HIGH Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of servic | May 29, 2018 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecstatic Project.
Media articles that mention a CVE ID that affects a product developed by Ecstatic Project — matched by CVE ID, not by vendor name.