High severity7.5NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026
CVE-2023-30591
CVE-2023-30591
Description
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking eventName.startsWith() or eventName.toString(), while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- NodeBB, Inc./NodeBBv5Range: 0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.