Executive brief
ecstatic is a Node.js middleware for serving static files. An attacker can crash the server by sending HTTP requests with payloads containing large numbers of null bytes (%00), causing the server to consume memory until it crashes. This impacts availability of web applications relying on ecstatic for asset delivery.
Technical details
The vulnerability is a denial of service caused by improper handling of null bytes in URL paths. ecstatic previously stripped null bytes from URLs as a workaround for an old Node.js url.parse bug, but removal of this filtering exposed a regex-based denial-of-service attack vector. An unauthenticated network attacker can send crafted HTTP requests with null-byte-laden payloads to trigger excessive memory allocation and crash the server. A 86 kB payload was observed to cause immediate crash. The vulnerability affects all versions prior to 2.0.0, which restored null-byte filtering to mitigate the issue.
Affected products
- npm ecstatic <2.0.0
Timeline
- 2017-12-14: disclosed
- 2.0.0: patched: Fixed by restoring null-byte filtering
- 2017-12-28: advisory