VDB
Sign up
HIGH7.5

GHSA-pm9p-9926-w68m

Denial of Service in ecstatic

Quick fix

GHSA-pm9p-9926-w68m — ecstatic: upgrade to the fixed version with the command below.

npm install ecstatic@2.0.0

Details

`ecstatic`, a simple static file server middleware, is vulnerable to denial of service. If a payload with a large number of null bytes (`%00`) is provided by an attacker it can crash ecstatic by running it out of memory.

[Results from the original advisory](https://www.checkmarx.com/advisories/denial-of-service-dos-vulnerability-in-ecstatic-npm-package/)

``` A payload of 22kB caused a lag of 1 second, A payload of 35kB caused a lag of 3 seconds, A payload of 86kB caused the server to crash ```

## Recommendation

Update to version 2.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ecstatic
Introduced in: 0Fixed in: 2.0.0
Fixnpm install ecstatic@2.0.0

References