Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 10.0.10240.19145 |
| n/a | n/a | n/a |