CVE-2013-4450

Nodejs - Improper Input Validation

Title source: rule

Description

The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.

Exploits (1)

metasploit WORKING POC
by Marek Majkowski, titanous, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/nodejs_pipelining.rb

Scores

EPSS 0.6871
EPSS Percentile 98.6%

Classification

CWE
CWE-20
Status draft

Affected Products (47)

nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
... and 32 more

Timeline

Published Oct 21, 2013
Tracked Since Feb 18, 2026