Disclosing uncontrolled resource consumption in xmlhttprequest library
Read OriginalThe article details a security vulnerability (CWE-400) discovered in the xmlhttprequest npm library, which lacks timeout controls for outgoing HTTP requests. This allows attackers to force connections to hang indefinitely, potentially saturating server I/O resources. It includes proof-of-concept exploit code and discusses the maintainer's response.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser