CVE-2025-11149 affects all versions of node-static. The package fails to catch exceptions when user input includes null bytes, allowing attackers to crash the server with requests like http://host/%00.
References
https://nvd.nist.gov/vuln/detail/CVE-2025-11149
https://security-tracker.debian.org/tracker/CVE-2025-11149
78879dc
CVE-2025-11149 affects all versions of node-static. The package fails to catch exceptions when user input includes null bytes, allowing attackers to crash the server with requests like http://host/%00.
References
https://nvd.nist.gov/vuln/detail/CVE-2025-11149
https://security-tracker.debian.org/tracker/CVE-2025-11149
78879dc