Filtered by vendor @nubosoftware/node-static Project Subscriptions
Filtered by product @nubosoftware/node-static Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-11149 2 @nubosoftware/node-static Project, Node-static Project 2 @nubosoftware/node-static, Node-static 2025-10-02 7.5 High
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.