PT-2025-39959 · Unknown+1 · Node-Static+2
Unknown
·
Published
2021-09-22
·
Updated
2025-10-05
·
CVE-2025-11149
CVSS v3.1
7.5
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
node-static (affected versions not specified)
@nubosoftware/node-static (affected versions not specified)
Description
The software does not properly handle user input containing null bytes. This can allow attackers to access
http://host/%00 and cause the server to crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Nubosoftware/Node-Static
Debian
Node-Static