Denial of Service in node-static
Moderate severity
GitHub Reviewed
Published
Sep 22, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Sep 22, 2021
Published to the GitHub Advisory Database
Sep 22, 2021
Last updated
Jan 9, 2023
All versions of node-static are vulnerable to a Denial of Service. The package fails to catch an exception when user input includes null bytes. This allows attackers to access
http://host/%00
and crash the server.References