http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks

Disclosed: 2024-03-05 12:09:56 By bart To ibb
High
Vulnerability Details
I'd like to report Node.js vulnerability (CVE-2024-22019) that was recently fixed: - HackerOne report: https://hackerone.com/reports/2233486 - Release notes: https://nodejs.org/en/blog/vulnerability/february-2024-security-releases ## Impact This is a major issue because it allows unbounded resource (CPU, network bandwidth) consumption of the standard Node.js http server. The standard methods which could help blocking a malicious requests like timeouts and limiting request body size do not seem to work.
Actions
View on HackerOne
Report Stats
  • Report ID: 2375446
  • State: Closed
  • Substate: resolved
  • Upvotes: 40
Share this report