Node-Static and Nubosoftware/Node-Static Vulnerability in Node.js Packages
CVE-2025-11149
What is CVE-2025-11149?
The vulnerability affecting the Node-Static and Nubosoftware/Node-Static packages arises from a failure to properly handle user input containing null bytes. As a result, attackers can exploit this flaw to access resources in a manner not intended by the developers, specifically through crafted URLs like http://host/%00. This situation may lead to server crashes, potentially disrupting service availability. Developers are urged to implement input validation and consider upgrading to patched versions to safeguard their applications from exploits leveraging this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
@nubosoftware/node-static 0
node-static 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
