CVE Vulnerabilities

CVE-2015-8027

Published: Jan 02, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.

Affected Software

NameVendorStart VersionEnd Version
Node.jsNodejs0.12.0 (including)0.12.0 (including)
Node.jsNodejs0.12.1 (including)0.12.1 (including)
Node.jsNodejs0.12.2 (including)0.12.2 (including)
Node.jsNodejs0.12.3 (including)0.12.3 (including)
Node.jsNodejs0.12.4 (including)0.12.4 (including)
Node.jsNodejs0.12.5 (including)0.12.5 (including)
Node.jsNodejs0.12.6 (including)0.12.6 (including)
Node.jsNodejs0.12.7 (including)0.12.7 (including)
Node.jsNodejs0.12.8 (including)0.12.8 (including)
Node.jsNodejs4.2.0 (including)4.2.0 (including)
Node.jsNodejs4.2.1 (including)4.2.1 (including)
Node.jsNodejs4.2.2 (including)4.2.2 (including)
Node.jsNodejs5.0.0 (including)5.0.0 (including)
Node.jsNodejs5.1.0 (including)5.1.0 (including)
NodejsUbuntuartful*
NodejsUbuntuprecise*
NodejsUbuntuupstream*
NodejsUbuntuvivid*
NodejsUbuntuwily*
NodejsUbuntuyakkety*
NodejsUbuntuzesty*

References