CVE-2017-16025
Denial of Service in nes
EPSS 0.36%
Description
Affected versions of `nes` are vulnerable to denial of service when given an invalid `cookie` header, and websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to throw and exit. ## Recommendation Update to version 6.4.1 or later.
How to fix CVE-2017-16025
To remediate CVE-2017-16025, upgrade the affected package to a fixed version below.
- npm/nes—upgrade to 6.4.1 or later
Is CVE-2017-16025 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 6.4.1