Disclosing uncontrolled resource consumption in xmlhttprequest library
Read OriginalThe article details a security vulnerability (CWE-400) discovered in the xmlhttprequest npm library, which lacks timeout controls for outgoing HTTP requests. This allows attackers to force connections to hang indefinitely, potentially saturating server I/O resources. It includes proof-of-concept exploit code and discusses the maintainer's response.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
No top articles yet