Node-Static and Nubosoftware/Node-Static Vulnerability in Node.js Packages
CVE-2025-11149

7.5HIGH

Key Information:

Vendor
CVE Published:
30 September 2025

What is CVE-2025-11149?

The vulnerability affecting the Node-Static and Nubosoftware/Node-Static packages arises from a failure to properly handle user input containing null bytes. As a result, attackers can exploit this flaw to access resources in a manner not intended by the developers, specifically through crafted URLs like http://host/%00. This situation may lead to server crashes, potentially disrupting service availability. Developers are urged to implement input validation and consider upgrading to patched versions to safeguard their applications from exploits leveraging this vulnerability.

Affected Version(s)

@nubosoftware/node-static 0

node-static 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Unknown
.
CVE-2025-11149 : Node-Static and Nubosoftware/Node-Static Vulnerability in Node.js Packages