Node-Static and Nubosoftware/Node-Static Vulnerability in Node.js Packages
CVE-2025-11149
7.5HIGH
What is CVE-2025-11149?
The vulnerability affecting the Node-Static and Nubosoftware/Node-Static packages arises from a failure to properly handle user input containing null bytes. As a result, attackers can exploit this flaw to access resources in a manner not intended by the developers, specifically through crafted URLs like http://host/%00. This situation may lead to server crashes, potentially disrupting service availability. Developers are urged to implement input validation and consider upgrading to patched versions to safeguard their applications from exploits leveraging this vulnerability.
Affected Version(s)
@nubosoftware/node-static 0
node-static 0