CVE-2013-4450
Nodejs - Improper Input Validation
Title source: ruleDescription
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Exploits (1)
metasploit
WORKING POC
by Marek Majkowski, titanous, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/nodejs_pipelining.rb
References (10)
Scores
EPSS
0.6871
EPSS Percentile
98.6%
Classification
CWE
CWE-20
Status
draft
Affected Products (47)
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
nodejs/nodejs
... and 32 more
Timeline
Published
Oct 21, 2013
Tracked Since
Feb 18, 2026