suse · CVE-2018-12121

Quick triage

Priority: medium Published: 2021-05-30 14:14:00 UTC Updated: 2025-11-05 03:29:08 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-12121 severity moderate: SUSE including 76 source package names (MozillaFirefox-68.2.0-78.51.4, MozillaFirefox-branding-SLED-68-21.9.8, …), 237 product×package rows across 32 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 4, … (32 product lines)): Fixed 170, Known Not Affected 67.

Description:

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.

cvelogic Threat Intelligence