A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/11/1 | Mailing List Third Party Advisory |
| https://hackerone.com/reports/2233486 | Issue Tracking |
| https://security.netapp.com/advisory/ntap-20240315-0004/ | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/03/11/1 | Mailing List Third Party Advisory |
| https://hackerone.com/reports/2233486 | Issue Tracking |
| https://security.netapp.com/advisory/ntap-20240315-0004/ | Third Party Advisory |
Configurations
History
02 Apr 2025, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netapp
Netapp astra Control Center Nodejs Nodejs node.js |
|
| References | () http://www.openwall.com/lists/oss-security/2024/03/11/1 - Mailing List, Third Party Advisory | |
| References | () https://hackerone.com/reports/2233486 - Issue Tracking | |
| References | () https://security.netapp.com/advisory/ntap-20240315-0004/ - Third Party Advisory | |
| CPE | cpe:2.3:a:netapp:astra_control_center:-:*:*:*:*:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
Information
Published : 2024-02-20 02:15
Updated : 2025-04-02 20:10
NVD link : CVE-2024-22019
Mitre link : CVE-2024-22019
CVE.ORG link : CVE-2024-22019
JSON object : View
Products Affected
nodejs
- node.js
netapp
- astra_control_center
CWE
CWE-404
Improper Resource Shutdown or Release
