Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34461.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-34461
Upstream
Published
2024-02-20T02:15:50Z
Modified
2026-04-01T05:11:28.739724Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
CVE-2024-22019 affecting package nodejs18 for versions less than 18.20.2-1
Details

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

References

Affected packages

Azure Linux:2 / nodejs18

Package

Name
nodejs18
Purl
pkg:rpm/azure-linux/nodejs18

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.20.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34461.json"