HIGH7.5
GHSA-pm9p-9926-w68m
Denial of Service in ecstatic
Quick fix
GHSA-pm9p-9926-w68m — ecstatic: upgrade to the fixed version with the command below.
npm install ecstatic@2.0.0Details
`ecstatic`, a simple static file server middleware, is vulnerable to denial of service. If a payload with a large number of null bytes (`%00`) is provided by an attacker it can crash ecstatic by running it out of memory.
[Results from the original advisory](https://www.checkmarx.com/advisories/denial-of-service-dos-vulnerability-in-ecstatic-npm-package/)
``` A payload of 22kB caused a lag of 1 second, A payload of 35kB caused a lag of 3 seconds, A payload of 86kB caused the server to crash ```
## Recommendation
Update to version 2.0.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-10703[ADVISORY]
- https://github.com/jfhbrook/node-ecstatic/commit/71ce93988ead4b561a8592168c72143907189f01[WEB]
- https://github.com/jfhbrook/node-ecstatic/commit/71ce93988ead4b561a8592168c72143907189f01#diff-b2b5a88fb51675f1aa1065c093dce1ee[WEB]
- https://advisory.checkmarx.net/advisory/CX-2016-4450[WEB]
- https://github.com/advisories/GHSA-pm9p-9926-w68m[ADVISORY]
- https://github.com/jfhbrook/node-ecstatic[PACKAGE]
- https://www.checkmarx.com/advisories/denial-of-service-dos-vulnerability-in-ecstatic-npm-package[WEB]
- https://www.npmjs.com/advisories/553[WEB]