PT-2019-17836 · Node.Js+7 · Node.Js+7

Jan Maybach

+1

·

Published

2019-01-28

·

Updated

2026-05-18

·

CVE-2019-5737

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 6.x before 6.17.0 Node.js versions 8.x before 8.15.1 Node.js versions 10.x before 10.15.2 Node.js versions 11.x before 11.10.1
Description An attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and sending headers very slowly, keeping the connection and associated resources alive for a long period. Potential attacks are mitigated by the use of a load balancer or other proxy layer.
Recommendations For Node.js versions 6.x before 6.17.0, update to version 6.17.0 or later. For Node.js versions 8.x before 8.15.1, update to version 8.15.1 or later. For Node.js versions 10.x before 10.15.2, update to version 10.15.2 or later. For Node.js versions 11.x before 11.10.1, update to version 11.10.1 or later. As a temporary workaround, consider implementing a load balancer or other proxy layer to mitigate potential attacks.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2925
ALT-PU-2019-1385
BDU:2026-01436
CESA-2019_2925
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2019-5737
MGASA-2019-0277
OPENSUSE-SU-2019_1076-1
OPENSUSE-SU-2019_1173-1
OPENSUSE-SU-2019_1211-1
RHSA-2019:1821
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019_2925
RLSA-2019:2925
SUSE-SU-2019:0627-1
SUSE-SU-2019:0635-1
SUSE-SU-2019:0636-1
SUSE-SU-2019:0658-1
SUSE-SU-2019:0818-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_0627-1
SUSE-SU-2019_0635-1
SUSE-SU-2019_0636-1
SUSE-SU-2019_14246-1
USN-4796-1

Affected Products

Alt Linux
Almalinux
Centos
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu