Denial of Service in ecstatic
High severity
GitHub Reviewed
Published
Dec 28, 2017
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Published by the National Vulnerability Database
Dec 14, 2017
Published to the GitHub Advisory Database
Dec 28, 2017
Reviewed
Jun 16, 2020
Last updated
Apr 11, 2023
ecstatic
, a simple static file server middleware, is vulnerable to denial of service. If a payload with a large number of null bytes (%00
) is provided by an attacker it can crash ecstatic by running it out of memory.Results from the original advisory
Recommendation
Update to version 2.0.0 or later.
References