Denial of Service in node-static
Moderate severity
GitHub Reviewed
Published
Sep 22, 2021
to the GitHub Advisory Database
•
Updated Oct 3, 2025
Description
Reviewed
Sep 22, 2021
Published to the GitHub Advisory Database
Sep 22, 2021
Last updated
Oct 3, 2025
All versions of node-static are vulnerable to a Denial of Service. The package fails to catch an exception when user input includes null bytes. This allows attackers to access
http://host/%00
and crash the server.References