7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:R
Description
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
Basic Information
ID
CVE-2025-11149
Source
snyk
Published
Sep 30, 2025 at 05:00
Affected Product
Vendor
n/a
Product
node-static
Affected Versions
n/a node-static 0
n/a @nubosoftware/node-static 0
n/a @nubosoftware/node-static 0