CVE-2022-25940

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lite-server_project:lite-server:-:*:*:*:*:node.js:*:*

History

16 Apr 2025, 19:15

Type Values Removed Values Added
CWE CWE-20

21 Nov 2024, 06:53

Type Values Removed Values Added
References () https://gist.github.com/lirantal/832382155e00da92bfd8bb3adea474eb - Exploit, Third Party Advisory () https://gist.github.com/lirantal/832382155e00da92bfd8bb3adea474eb - Exploit, Third Party Advisory
References () https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3175617 - Exploit, Third Party Advisory () https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3175617 - Exploit, Third Party Advisory
References () https://security.snyk.io/vuln/SNYK-JS-LITESERVER-3153540 - Exploit, Third Party Advisory () https://security.snyk.io/vuln/SNYK-JS-LITESERVER-3153540 - Exploit, Third Party Advisory

20 Dec 2022, 06:15

Type Values Removed Values Added
Summary All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse. All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

20 Dec 2022, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-20 05:15

Updated : 2025-04-16 19:15


NVD link : CVE-2022-25940

Mitre link : CVE-2022-25940

CVE.ORG link : CVE-2022-25940


JSON object : View

Products Affected

lite-server_project

  • lite-server
CWE
NVD-CWE-Other CWE-20

Improper Input Validation