Liran Tal 4/16/2023

Disclosing uncontrolled resource consumption in xmlhttprequest library

Read Original

The article details a security vulnerability (CWE-400) discovered in the xmlhttprequest npm library, which lacks timeout controls for outgoing HTTP requests. This allows attackers to force connections to hang indefinitely, potentially saturating server I/O resources. It includes proof-of-concept exploit code and discusses the maintainer's response.

Disclosing uncontrolled resource consumption in xmlhttprequest library

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week