Executive brief
Oak Server is a web server framework for Deno used to build and run web applications. An attacker can craft specially malformed HTTP headers (x-forwarded-proto or x-forwarded-for) to cause the server to consume excessive CPU time, slowing it down significantly or causing a denial of service. A 128KB malicious header can cause processing delays of over 15 seconds.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the request header parsing logic for x-forwarded-proto and x-forwarded-for headers (CWE-1333). The vulnerable code uses inefficient regex patterns that exhibit exponential worst-case complexity when processing specially crafted input. An unauthenticated attacker can send HTTP requests with these malicious headers from the network without any user interaction required. Exploitation causes severe CPU consumption, degrading server performance or creating a denial-of-service condition. A patch is available in version 17.1.6 for the JSR package and deno.land/x distribution; the npm package has no patched version listed.
Affected products
- Oak Oak <=14.1.0 (npm); <=17.1.5 (deno.land/x, JSR)
Timeline
- 2025-08-08: disclosed
- 2025-08-12: advisory
- 2025-08-12: patched: Version 17.1.6 available for deno.land/x and JSR; npm package @oakserver/oak has no patch