Description
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
https://starlabs.sg/advisories/23/23-30591/
Scores
CVSS v3
7.5
EPSS
0.0221
EPSS Percentile
84.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-754
CWE-241
Status
published
Products (1)
nodebb/nodebb
< 2.8.10
Published
Sep 29, 2023
Tracked Since
Feb 18, 2026