← Vulnerability feed

Vulnerability record · CVE-2023-30591 · published 29 September 2023

CVE-2023-30591: NodeBB Socket.IO event name type confusion denial of service

Nodebb · Nodebb

NodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a string. The code calls eventName.startsWith() or eventName.toString() on the malformed value, causing an unhandled error that takes down the process. Because the trigger is unauthenticated, any network-reachable instance is exposed to repeated availability loss.

7.5 CVSS 3.1 High EPSS 54% · top 1.0% CWE-241 · CWE-241CWE-754 · CWE-754
7.5CVSS 3.1 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated remote crash with a high EPSS score and public patch commits, though no confirmed in-the-wild exploitation or KEV listing.

What it is

NodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a string. The code calls eventName.startsWith() or eventName.toString() on the malformed value, causing an unhandled error that takes down the process. Because the trigger is unauthenticated, any network-reachable instance is exposed to repeated availability loss.

Impact

An attacker can crash the NodeBB server process, denying forum service to all users. Repeated requests can keep the service down; there is no evidence of data access or code execution.

Attack surface

Reachable over the network through the Socket.IO endpoint; the CVSS vector shows no privileges and no user interaction required. Any client that can open a Socket.IO connection can send the malformed event name.

Exploitation

Not listed in CISA KEV and no public exploit tag is present, but EPSS is 0.53804 (98.9th percentile), indicating a high modeled likelihood of exploitation activity. Patch commits are public, which lowers the effort to reproduce.

What to do

  • Upgrade NodeBB to a version containing the three patch commits (37b48b82, 4d2d7689, 830f142b) or later; this is the primary fix.
  • If immediate upgrade is not possible, restrict network access to the Socket.IO endpoint to trusted clients and place the forum behind a reverse proxy or WAF that can reject malformed Socket.IO frames.
  • Run NodeBB under a process supervisor that restarts on crash, and alert on restart events to limit downtime.
  • Monitor the NodeBB repository and StarLabs advisory for updated guidance and any backported fixes.

Detection

  • Alert on NodeBB process crashes or unexpected restarts, especially clustered in time.
  • Inspect reverse proxy or Socket.IO logs for event names that are arrays or objects rather than strings.
  • Baseline normal Socket.IO event names and flag deviations, particularly from unauthenticated connections.
  • Correlate repeated connection attempts from a single source with subsequent service restarts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-30591 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15149Nodebb improper privilege management vulnerabilityNodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…EPSS 2.4%9.8CVE-2023-43187NodeBB xmlrpc.php XML injection leads to remote code executionNodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code th…EPSS 45%analysed9.8CVE-2023-26045Nodebb path traversal vulnerabilityNodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…EPSS 1.0%9.8CVE-2022-46164NodeBB socket.io prototype handling allows account takeoverNodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over a…EPSS 49%analysed9.8CVE-2022-36045Nodebb vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…EPSS 1.3%8.7CVE-2026-58593Nodebb authentication bypass by spoofing vulnerabilityNodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…EPSS 0.29%8.6CVE-2025-50979Nodebb sql injection vulnerabilityNodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…EPSS 8.5%7.5CVE-2022-36076Nodebb cross-site request forgery vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional …EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2023-30591), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.