Логотип exploitDog
bind:CVE-2016-10544
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-10544

Количество 2

Количество 2

nvd логотип

CVE-2016-10544

больше 7 лет назад

uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down to less than 16mb of websocket payload which passes the length check of 16mb payload. This data will then inflate up to 256mb and crash the node process by exceeding V8's maximum string size. This affects uws >=0.10.0 <=0.10.8.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-hf5h-hh56-3vrg

больше 5 лет назад

Denial of Service in uws

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-10544

uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down to less than 16mb of websocket payload which passes the length check of 16mb payload. This data will then inflate up to 256mb and crash the node process by exceeding V8's maximum string size. This affects uws >=0.10.0 <=0.10.8.

CVSS3: 5.9
0%
Низкий
больше 7 лет назад
github логотип
GHSA-hf5h-hh56-3vrg

Denial of Service in uws

0%
Низкий
больше 5 лет назад

Уязвимостей на страницу