CVE-2018-12122: Node.js
High severity, CVSS 7.5. EPSS: 41.3% chance of exploitation in the next 30 days.
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
Affected products
- Node.js Node.js: from 6.0.0, before 6.15.1 (fixed in 6.15.1); from 8.0.0, before 8.14.0 (fixed in 8.14.0); from 10.0.0, before 10.14.0 (fixed in 10.14.0); from 11.0.0, before 11.3.0 (fixed in 11.3.0)
- Suse Suse Enterprise Storage: version 4 only
- Suse Suse Linux Enterprise Server: version 12 only; version 15 only
- Suse Suse Openstack Cloud: version 7 only; version 8 only
Published 2018-11-28. Last modified 2026-10-08.