High severity7.5NVD Advisory· Published Jan 2, 2016· Updated May 6, 2026
CVE-2015-8027
CVE-2015-8027
Description
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.
Affected products
14cpe:2.3:a:nodejs:node.js:0.12.0:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:nodejs:node.js:0.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.3:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.4:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.6:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.7:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:0.12.8:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nodejs:node.js:5.1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/nvdVendor Advisory
- nodejs.org/en/blog/vulnerability/december-2015-security-releases/nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2016-01/msg00045.htmlnvd
- www.securityfocus.com/bid/78207nvd
- security.gentoo.org/glsa/201612-43nvd
News mentions
0No linked articles in our index yet.