Junglewise Threat Intelligence

CVE-2022-36127: Apache SkyWalking NodeJS Agent denial of service in header parsing

CVE-2022-36127 · Severity: low · CVSS 3.1 · Published 2022-07-19

Vendors: npm, Apache.

Executive brief

Apache SkyWalking NodeJS Agent is a performance monitoring tool that collects telemetry data from Node.js applications. A flaw in how the agent handles malformed SkyWalking headers can cause it to crash, making the instrumented application unavailable when the monitoring backend is unhealthy. An attacker could send HTTP requests with crafted headers to trigger this crash.

Technical details

The vulnerability is a denial-of-service condition in Apache SkyWalking NodeJS Agent versions prior to 0.5.1. When the agent receives an HTTP request containing an illegal or malformed SkyWalking header and cannot connect to the OAP (Observation Analysis Platform) backend due to it being unhealthy, the agent crashes instead of gracefully handling the error, causing the entire instrumented Node.js service to become unavailable. The attack requires network access to send HTTP requests but no authentication or special privileges. The vulnerability was patched in version 0.5.1.

Affected products

  • Apache SkyWalking NodeJS Agent prior to 0.5.1

Timeline

  • 2022-07-19: disclosed
  • 2022-07-19: patched: version 0.5.1 released

References