CVE-2015-8027 — Node.js vulnerability

CWE-179 documents8 sources
Severity
7.5HIGHNVD
EPSS
1.4%
top 19.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 2
Latest updateMay 17

Description

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

â–¶Debiannodejs/nodejs< 4.2.3~dfsg-1+3
â–¶NVDnodejs/node.js14 versions+13

🔴Vulnerability Details

3
GHSA
GHSA-pvxc-6v2c-cv7w: Node↗2022-05-17
â–¶
OSV
CVE-2015-8027: Node↗2016-01-02
â–¶
CVEList
CVE-2015-8027: Node↗2016-01-02
â–¶

📋Vendor Advisories

3
Apple
CVE-2015-8027: Xcode 8.1↗2016-10-27
â–¶
Red Hat
nodejs: unspecified denial of service vulnerability↗2015-11-25
â–¶
Debian
CVE-2015-8027: nodejs - Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not en...↗2015
â–¶

💬Community

2
Bugzilla
CVE-2015-8027 nodejs: unspecified denial of service vulnerability↗2015-11-26
â–¶
Bugzilla
CVE-2015-1545 openldap: slapd crashes on search with deref control and empty attr list↗2015-02-09
â–¶
CVE-2015-8027 — Nodejs Node.js vulnerability | cvebase