← All CVEs

CVE-2018-12122

high · 7.5

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

7.5
CVSS
41.3%
EPSS (exploit prob.)
99th
EPSS percentile
2018-11-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
nodejsnode.js>= 6.0.0, < 6.15.1
nodejsnode.js>= 8.0.0, < 8.14.0
nodejsnode.js>= 10.0.0, < 10.14.0
nodejsnode.js>= 11.0.0, < 11.3.0
susesuse_enterprise_storage4
susesuse_linux_enterprise_server12
susesuse_linux_enterprise_server15
susesuse_openstack_cloud7
susesuse_openstack_cloud8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-12122