Vulnerability Description
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | >= 6.0.0, < 6.15.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 8.1 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Tus | 8.2 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106043Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1821Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2258Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3497Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/PatchVendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- http://www.securityfocus.com/bid/106043Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1821Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2258Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3497Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/PatchVendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241227-0008/
FAQ
What is CVE-2018-12121?
CVE-2018-12121 is a vulnerability with a CVSS score of 7.5 (HIGH). Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB p...
How severe is CVE-2018-12121?
CVE-2018-12121 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12121?
Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server.