CVE-2024-22019

7.5 HIGH
Published: February 20, 2024 Modified: November 04, 2025

Description

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/11/1
Source: support@hackerone.com
Mailing List Third Party Advisory
https://hackerone.com/reports/2233486
Source: support@hackerone.com
Issue Tracking
https://security.netapp.com/advisory/ntap-20240315-0004/
Source: support@hackerone.com
Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/11/1
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
https://hackerone.com/reports/2233486
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
https://security.netapp.com/advisory/ntap-20240315-0004/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

7 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.2%
42th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

nodejs netapp