Denial of Service Vulnerability in Node.js by Joyent
CVE-2019-5739
7.5HIGH
What is CVE-2019-5739?
The vulnerability allows keep-alive HTTP and HTTPS connections to remain open and inactive for up to 2 minutes in Node.js versions prior to 6.17.0. This behavior poses a potential Denial of Service attack vector, allowing attackers to exploit resource consumption by keeping connections open without activity. Node.js 6.17.0 introduced a dedicated server.keepAliveTimeout feature, reducing the default inactivity timeout to 5 seconds, thus mitigating this issue.
Affected Version(s)
Node.js All versions prior to 6.17.0