Description
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-pvxc-6v2c-cv7w: Node↗2022-05-17 ▶ OSVCVE-2015-8027: Node↗2016-01-02 ▶ CVEListCVE-2015-8027: Node↗2016-01-02 ▶ 📋Vendor Advisories
3AppleCVE-2015-8027: Xcode 8.1↗2016-10-27 ▶ Red Hatnodejs: unspecified denial of service vulnerability↗2015-11-25 ▶ DebianCVE-2015-8027: nodejs - Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not en...↗2015 ▶ 💬Community
2BugzillaCVE-2015-8027 nodejs: unspecified denial of service vulnerability↗2015-11-26 ▶ BugzillaCVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list↗2015-02-09 ▶