GHSA-3pwh-5mmc-mwrx
GitHub Security Advisory
Denial of Service in nes
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Affected versions of `nes` are vulnerable to denial of service when given an invalid `cookie` header, and websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to throw and exit.
## Recommendation
Update to version 6.4.1 or later.
Affected Packages
npm
nes
Affected versions:
0
(fixed in 6.4.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.