CVE-2025-11149 Details
Description
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
A denial-of-service vulnerability has been identified in all versions of the Node-Static package and the @Nubosoftware/Node-Static package. The issue arises because the packages do not properly handle user input that includes null bytes, allowing attackers to send requests that crash the server. This vulnerability can be exploited by accessing a URL with a null byte, which causes the server to fail.
A fix for this vulnerability has been implemented in the master branch of the Node-Static repository, but it has not yet been published. Users can monitor the repository for the release of the patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2025CISA-ADP
Assessed Sep 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cloudhead/node-static/commit/78879dc665f0f7137063794b6e0b6203a81c7f67 | [email protected] | Source CodeVendor |
| https://security.snyk.io/vuln/SNYK-JS-NODESTATIC-1297183 | [email protected] | AdvisoryRemedy |
| https://security.snyk.io/vuln/SNYK-JS-NUBOSOFTWARENODESTATIC-3330728 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cloudhead node-static | < 0.1.1 (semver) |
CPE
Remediation
| |
| @nubosoftware/node-static | < 0.1.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | New CVE Received | [email protected] |
Volerion