CVE Feed

    Dashboard / CVE / CVE-2017-11499

    CVE-2017-11499

    Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

    Published:Jul 11, 2017
    Last Modified:Apr 20, 2025
    EPS:Jul 25, 2017
    EPSS Score:0.00323
    CVSS Score:7.5

    Affected Products

    Vendor
    Nodejs
    Product
    Node.js
    Vendor
    Redhat
    Product
    Rhel Software Collections

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High