CVE 7.5 HIGH

CVE-2025-11149_CVE-2025-11149

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:R

Description

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

Basic Information

ID CVE-2025-11149
Source snyk
Published Sep 30, 2025 at 05:00

Affected Product

Vendor n/a
Product node-static
Affected Versions n/a node-static 0
n/a @nubosoftware/node-static 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.