Skip to content

[SECURITY] CVE-2025-11149: Null Byte Causes Server Crash #244

Description

@peterbernhardt

CVE-2025-11149 affects all versions of node-static. The package fails to catch exceptions when user input includes null bytes, allowing attackers to crash the server with requests like http://host/%00.

References
https://nvd.nist.gov/vuln/detail/CVE-2025-11149
https://security-tracker.debian.org/tracker/CVE-2025-11149
78879dc

Activity

  1. brettz9 commented on Oct 15, 2025

    @brettz9
    Collaborator

    Thank you for the report. I believe this should already be fixed in master, but we are awaiting a possible transfer of ownership in order to get out a release.

  2. brettz9 commented on Oct 15, 2025

    @brettz9
    Collaborator

    Closing as we can track the need for an npm release in #231 .

  3. peterbernhardt commented on Oct 16, 2025

    @peterbernhardt
    Author

    @brettz9 when can we expect a new release?

  4. brettz9 commented on Oct 16, 2025

    @brettz9
    Collaborator

    See my comment at #231 . Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions