CVE-2015-9242: Ecstatic Project Ecstatic

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.

Affected products

Published 2018-05-29. Last modified 2026-06-17.