Denial Of Service (DoS)
Discription

ws is vulnerable to Denial Of Service (DoS). The vulnerability is due to improper handling of the Upgrade header when the number of received headers exceeds the server.maxHeadersCount or request.maxHeadersCount threshold, causing incomingMessage.headers.upgrade to not be set. Attackers can use this to crash the ws server by sending a request with an excessive number of…Read More

Back to Main

Subscribe for the latest news: