« List of all CVEs

CVE-2018-7162

Published: 6/13/2018 Last updated: 9/16/2024 Reserved: 2/15/2018

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CNA assigner: nodejs (386269d4-a6c6-4eaa-bf8e-bc0b0d010558) Requested by: n/a

Opam packages affected (1)

conf-npm

Products affected (1)

Product Vendor Version
Node.js The Node.js Project 2008 R2 for Itanium-Based Systems Service Pack 1

References (6)