CVE-2013-4450
Nodejs - Improper Input Validation
Title source: ruleDescription
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Exploits (1)
metasploit
WORKING POC
by Marek Majkowski, titanous, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/nodejs_pipelining.rb
References (10)
Scores
EPSS
0.6871
EPSS Percentile
98.6%
Details
CWE
CWE-20
Status
published
Products (47)
nodejs/nodejs
0.8.0
nodejs/nodejs
0.8.1
nodejs/nodejs
0.8.2
nodejs/nodejs
0.8.3
nodejs/nodejs
0.8.4
nodejs/nodejs
0.8.5
nodejs/nodejs
0.8.6
nodejs/nodejs
0.8.7
nodejs/nodejs
0.8.8
nodejs/nodejs
0.8.9
... and 37 more
Published
Oct 21, 2013
Tracked Since
Feb 18, 2026