Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Timur Shemsedinov

#39168of 56,334
7.5Total CVSS
Vulnerabilities · 1
PT-2019-17837
7.5
2018-05-25
Node.Js · Node.Js · CVE-2019-5739
**Name of the Vulnerable Software and Affected Versions** Node.js versions prior to 6.17.0 **Description** The issue allows HTTP and HTTPS connections to remain open and inactive for an extended period, which can be exploited as a potential Denial of Service (DoS) attack vector. This behavior is due to the lack of a dedicated timeout setting in affected versions. The estimated number of potentially affected devices worldwide is not specified. **Recommendations** For Node.js versions prior to 6.17.0, consider introducing a timeout setting, such as server.keepAliveTimeout, to mitigate the risk of Denial of Service (DoS) attacks, ideally setting it to a default of 5 seconds as introduced in later versions.