Junglewise Threat Intelligence

CVE-2025-11149: node-static exception handling denial of service via null byte

CVE-2025-11149 · Severity: low · CVSS 3.1 · Published 2025-09-30

Vendors: npm.

Executive brief

node-static is a static file serving module for Node.js used to serve web content. A flaw in exception handling allows remote attackers to crash the server by sending a simple HTTP request with a null byte in the URL path. This results in complete service outage with no authentication or user interaction required, leaving web services relying on this module unable to serve content to legitimate users.

Technical details

This is a denial-of-service vulnerability caused by an uncaught exception in the node-static library (CWE-400: Uncontrolled Resource Consumption). The root cause is the module's failure to properly validate and catch exceptions when user input contains null bytes (\x00). When a request arrives with a null byte in the URL path (e.g., http://host/%00), the underlying filesystem call (fs.stats or similar path operation) throws an exception that is not caught, crashing the Node.js process. The attack vector is network-based with no privileges or authentication required. Any attacker with network access to the server can trigger the crash by sending a single malicious HTTP request. A patch was committed to the master branch (commit 78879dc) with the message "Protect fs.stats calls from bad path arguments," indicating the fix wraps filesystem calls in proper exception handling.

Affected products

  • cloudhead node-static all versions
  • nubosoftware @nubosoftware/node-static up to 0.7.11

Timeline

  • 2025-09-30: disclosed: CVE-2025-11149 published
  • 2025-09-30: patched: Fix committed to master branch (commit 78879dc)

References

Related threats