CVE-2017-16129

MEDIUM

superagent < 3.7.0 - Denial of Service via ZIP Bomb Response

Title source: llm
STIX 2.1

Description

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/479
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/visionmedia/superagent/issues/1259

Scores

CVSS v3 5.9
EPSS 0.0177
EPSS Percentile 75.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400 CWE-409
Status published
Products (2)
npm/superagent 0 - 3.7.0npm
superagent_project/superagent < 3.7.0
Published Jun 07, 2018
Tracked Since Feb 18, 2026