Denial of Service Vulnerability in Node.js by Node.js Foundation
CVE-2018-7162
7.5HIGH
What is CVE-2018-7162?
A vulnerability exists in Node.js versions 9.x and 10.x that allows an attacker to trigger a Denial of Service (DoS) by causing a node process, which runs an HTTP server with TLS support, to crash. This can be initiated through the transmission of duplicate or unexpected messages during the TLS handshake process. The issue has been mitigated through updates to the TLS implementation.
Affected Version(s)
Node.js 9.x+
Node.js 10.x+