CVE-2013-4450

Nodejs - Improper Input Validation

Title source: rule

Description

The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.

Exploits (1)

metasploit WORKING POC
by Marek Majkowski, titanous, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/nodejs_pipelining.rb

Scores

EPSS 0.6871
EPSS Percentile 98.6%

Details

CWE
CWE-20
Status published
Products (47)
nodejs/nodejs 0.8.0
nodejs/nodejs 0.8.1
nodejs/nodejs 0.8.2
nodejs/nodejs 0.8.3
nodejs/nodejs 0.8.4
nodejs/nodejs 0.8.5
nodejs/nodejs 0.8.6
nodejs/nodejs 0.8.7
nodejs/nodejs 0.8.8
nodejs/nodejs 0.8.9
... and 37 more
Published Oct 21, 2013
Tracked Since Feb 18, 2026