nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks
Published Feb 20, 2024
7.5
HIGHCVSS 3.1
EPSS 3.17%
Description
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.*
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.*
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.*
- Version 17.0StatusaffectedConstraints<17.*
- Version 18.0StatusaffectedConstraints<18.19.1
- Version 19.0StatusaffectedConstraints<19.*
- Version 20.0StatusaffectedConstraints<20.11.1
- Version 21.0StatusaffectedConstraints<21.6.2
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
-
- Version 0StatusaffectedConstraints<=21.6.1
- Version
Red Hat Enterprise Linux 8
nodejs:16-8090020240315081818.a75119d5
Fixed · RHSA-2024:1444
Red Hat Enterprise Linux 8
nodejs:18-8090020240301110609.a75119d5
Fixed · RHSA-2024:1510
Red Hat Enterprise Linux 8
nodejs:20-8090020240228165436.a75119d5
Fixed · RHSA-2024:1687
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:16-8060020240318185600.ad008a3a
Fixed · RHSA-2024:2793
Red Hat Enterprise Linux 8.8 Extended Update Support
nodejs:16-8080020240318185426.63b34585
Fixed · RHSA-2024:2651
Red Hat Enterprise Linux 8.8 Extended Update Support
nodejs:18-8080020240322102042.63b34585
Fixed · RHSA-2024:1880
Red Hat Enterprise Linux 9
nodejs-1:16.20.2-4.el9_3
Fixed · RHSA-2024:1438
Red Hat Enterprise Linux 9
nodejs:18-9030020240301111035.rhel9
Fixed · RHSA-2024:1503
Red Hat Enterprise Linux 9
nodejs:20-9030020240229115828.rhel9
Fixed · RHSA-2024:1688
Red Hat Enterprise Linux 9.0 Extended Update Support
nodejs-1:16.20.2-4.el9_0
Fixed · RHSA-2024:1424
Red Hat Enterprise Linux 9.2 Extended Update Support
nodejs-1:16.20.2-4.el9_2
Fixed · RHSA-2024:1678
Red Hat Enterprise Linux 9.2 Extended Update Support
nodejs:18-9020020240322155241.rhel9
Fixed · RHSA-2024:1932
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.21.3-6.el7
Fixed · RHSA-2024:1354
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:16-8090020240315081818.a75119d5 | Fixed | RHSA-2024:1444 |
| Red Hat Enterprise Linux 8 | nodejs:18-8090020240301110609.a75119d5 | Fixed | RHSA-2024:1510 |
| Red Hat Enterprise Linux 8 | nodejs:20-8090020240228165436.a75119d5 | Fixed | RHSA-2024:1687 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:16-8060020240318185600.ad008a3a | Fixed | RHSA-2024:2793 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | nodejs:16-8080020240318185426.63b34585 | Fixed | RHSA-2024:2651 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | nodejs:18-8080020240322102042.63b34585 | Fixed | RHSA-2024:1880 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.20.2-4.el9_3 | Fixed | RHSA-2024:1438 |
| Red Hat Enterprise Linux 9 | nodejs:18-9030020240301111035.rhel9 | Fixed | RHSA-2024:1503 |
| Red Hat Enterprise Linux 9 | nodejs:20-9030020240229115828.rhel9 | Fixed | RHSA-2024:1688 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | nodejs-1:16.20.2-4.el9_0 | Fixed | RHSA-2024:1424 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | nodejs-1:16.20.2-4.el9_2 | Fixed | RHSA-2024:1678 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | nodejs:18-9020020240322155241.rhel9 | Fixed | RHSA-2024:1932 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.21.3-6.el7 | Fixed | RHSA-2024:1354 |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While this vulnerability in Node.js HTTP servers poses a significant risk to system stability and availability, it is classified as a important severity issue rather than a critical one due to several factors. Firstly, while the vulnerability can lead to denial of service (DoS) attacks by causing resource exhaustion, it does not directly compromise the confidentiality or integrity of data stored or processed by the server. Additionally, the exploit requires the attacker to send specially crafted HTTP requests, which may limit the ease and scope of potential attacks compared to more critical vulnerabilities that can be exploited remotely without specific conditions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Nov 7, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.17% (0.03168) | 87.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.17% (0.03168) | 86.31th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.20% (0.00196) | 41.76th | v4 (v2025.03.14) |
| Nov 18, 2025 | 7.70% (0.07700) | 91.03th | v4 (v2025.03.14) |
| Apr 3, 2025 | 0.08% (0.00085) | 22.01th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.10% (0.02098) | 82.49th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.34% (0.05342) | 83.07th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.10% (0.02098) | 82.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.70th | v3 (v2023.03.01) |
| May 2, 2024 | 0.04% (0.00045) | 14.32th | v3 (v2023.03.01) |
| Feb 20, 2024 | 0.04% (0.00043) | 6.73th | v3 (v2023.03.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2024/03/11/1 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-22019 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2264574 Issue Tracking
- https://hackerone.com/reports/2233486 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-22019
- https://security.netapp.com/advisory/ntap-20240315-0004/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-22019
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/11/1 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2024-22019 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2264574 | Issue Tracking | |
| https://hackerone.com/reports/2233486 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-22019 | ||
| https://security.netapp.com/advisory/ntap-20240315-0004/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2024-22019 |
Change history (0)
No recorded changes yet.