PT-2023-8975 · Node.Js+8 · Node.Js+8

Bart

·

Published

2023-10-30

·

Updated

2025-08-29

·

CVE-2024-22019

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Node.js (affected versions not specified)
Description A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. This issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1438
ALSA-2024:1444
ALSA-2024:1503
ALSA-2024:1510
ALSA-2024:1687
ALSA-2024:1688
ALT-PU-2024-3054
ALT-PU-2025-2007
ALT-PU-2025-2047
AZL-34461
AZL-35047
BDU:2024-02798
BIT-NODE-2024-22019
BIT-NODE-MIN-2024-22019
CESA-2024_1444
CESA-2024_1510
CESA-2024_1687
CVE-2024-22019
DLA-3886-1
DSA-5991-1
ECHO-B80D-D824-90A1
MGASA-2024-0046
OESA-2024-2171
OESA-2024-2172
OESA-2024-2173
OESA-2024-2175
OPENSUSE-SU-2024:13697-1
OPENSUSE-SU-2024:13698-1
OPENSUSE-SU-2024_0728-1
OPENSUSE-SU-2024_0729-1
RHSA-2024:1354
RHSA-2024:1424
RHSA-2024:1438
RHSA-2024:1444
RHSA-2024:1503
RHSA-2024:1510
RHSA-2024:1678
RHSA-2024:1687
RHSA-2024:1688
RHSA-2024:1880
RHSA-2024:1932
RHSA-2024:2651
RHSA-2024:2793
RHSA-2024_1438
RHSA-2024_1444
RHSA-2024_1503
RHSA-2024_1510
RHSA-2024_1687
RHSA-2024_1688
RLSA-2024:1438
RLSA-2024:1444
RLSA-2024:1503
RLSA-2024:1510
RLSA-2024:1687
RLSA-2024:1688
SUSE-SU-2024:0643-1
SUSE-SU-2024:0644-1
SUSE-SU-2024:0728-1
SUSE-SU-2024:0729-1
SUSE-SU-2024:0730-1
SUSE-SU-2024:0731-1
SUSE-SU-2024:0732-1
SUSE-SU-2024:0733-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Node.Js
Red Hat
Red Os
Rocky Linux
Suse