Back

HIGH

nodejs: Insufficient Slowloris fix causing DoS via server.headersTimeout bypass

Published Mar 28, 2019

Description

In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.

Affected products

Remediation

Red Hat mitigation

The use of a Load Balancer or a Reverse Proxy will increase the difficulty of the attack.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner nodejs
Published Mar 28, 2019
Updated Aug 4, 2024
Reserved Jan 9, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 28, 2019