Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31700 | @nubosoftware/node-static failure to catch exception can result in server crash |
Github GHSA |
GHSA-27w5-gj5q-82fv | @nubosoftware/node-static failure to catch exception can result in server crash |
Fri, 03 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | node-static: node-static denial of service | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
@nubosoftware/node-static Project
@nubosoftware/node-static Project @nubosoftware/node-static Node-static Project Node-static Project node-static |
|
| Vendors & Products |
@nubosoftware/node-static Project
@nubosoftware/node-static Project @nubosoftware/node-static Node-static Project Node-static Project node-static |
Tue, 30 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Sep 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server. | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-09-30T19:07:09.035Z
Reserved: 2025-09-29T09:34:20.420Z
Link: CVE-2025-11149
Updated: 2025-09-30T19:07:05.429Z
Status : Deferred
Published: 2025-09-30T11:37:39.050
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11149
OpenCVE Enrichment
Updated: 2025-10-02T08:46:24Z
EUVD
Github GHSA