High severity7.5NVD Advisory· Published Feb 25, 2023· Updated Jun 17, 2026
CVE-2023-26104
CVE-2023-26104
Description
All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lite-web-servernpm | <= 1.2.2 | — |
Affected products
3- cpe:2.3:a:lite-web-server_project:lite-web-server:-:*:*:*:*:node.js:*:*
- lite-web-server/lite-web-serverdescription
Patches
Vulnerability mechanics
References
6- gist.github.com/lirantal/637520812da06fffb91dd86d02ff6bdenvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8237-3q5g-99fvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26104ghsaADVISORY
- security.snyk.io/vuln/SNYK-JS-LITEWEBSERVER-3153703nvdThird Party AdvisoryWEB
- github.com/chasyumen/lite-web-server/blob/main/src/WebServer.jsghsaWEB
- github.com/chasyumen/lite-web-server/blob/main/src/WebServer.js%23L274nvdBroken Link
News mentions
0No linked articles in our index yet.