VDB
Sign up
MEDIUM

GHSA-8r4g-cg4m-x23c

Denial of Service in node-static

Details

All versions of node-static are vulnerable to a Denial of Service. The package fails to catch an exception when user input includes null bytes. This allows attackers to access `http://host/%00` and crash the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-static
Introduced in: 0

No fixed version published yet for node-static (npm). Pin to a known-safe version or switch to an alternative.

References