← Vulnerability feed

Vulnerability record · CVE-2018-12122 · published 28 November 2018

CVE-2018-12122: Nodejs node.js uncontrolled resource consumption vulnerability

Nodejs · Node.Js

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

7.5 CVSS 3.1 High EPSS 41% · top 1.4% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 5.0
41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12122 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2016-3714ImageMagick coders allow command execution via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 fail to validate input in multiple coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT), allo…KEVEPSS 97%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed5.5CVE-2014-0196Linux kernel n_tty_write race condition allows local privilege escalationThe n_tty_write function in the Linux kernel through 3.14.3 mishandles tty driver access in the LECHO & !OPOST case, creating a race condition betwee…KEVEPSS 22%analysed10.0CVE-2026-21636Nodejs node.js improper access control vulnerabilityA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …EPSS 0.88%10.0CVE-2015-2738Canonical ubuntu linux vulnerabilityThe YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8…EPSS 2.7%10.0CVE-2015-2737Mozilla firefox vulnerabilityThe rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before …EPSS 2.7%10.0CVE-2015-2734Suse linux enterprise desktop vulnerabilityThe CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 a…EPSS 2.7%10.0CVE-2015-0278Fedoraproject fedora vulnerabilitylibuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2018-12122), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.