Junglewise Threat Intelligence

CVE-2016-10703: ecstatic denial of service via null byte payload

CVE-2016-10703 · Severity: low · CVSS 3.1 · Published 2017-12-28

Technologies: ecstatic (npm). Vendors: npm.

Executive brief

ecstatic is a Node.js middleware for serving static files. An attacker can crash the server by sending HTTP requests with payloads containing large numbers of null bytes (%00), causing the server to consume memory until it crashes. This impacts availability of web applications relying on ecstatic for asset delivery.

Technical details

The vulnerability is a denial of service caused by improper handling of null bytes in URL paths. ecstatic previously stripped null bytes from URLs as a workaround for an old Node.js url.parse bug, but removal of this filtering exposed a regex-based denial-of-service attack vector. An unauthenticated network attacker can send crafted HTTP requests with null-byte-laden payloads to trigger excessive memory allocation and crash the server. A 86 kB payload was observed to cause immediate crash. The vulnerability affects all versions prior to 2.0.0, which restored null-byte filtering to mitigate the issue.

Affected products

  • npm ecstatic <2.0.0

Timeline

  • 2017-12-14: disclosed
  • 2.0.0: patched: Fixed by restoring null-byte filtering
  • 2017-12-28: advisory

References

Related threats