← Back to browse · API

CVE-2023-30591

Severity
HIGH
CVSS
7.5
EPSS
0.53804
Risk score
48.83
CISA KEV
No
PoC
No
Published
2023-09-29
Modified
2024-09-23
First seen
2026-08-07
Aliases
EUVD-2023-34971, GHSA-MP98-Q49W-JJHW
Products
NodeBB:NodeBB 0 ≤2.8.10
Sources
euvd EUVD-2023-34971

Description

Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.

References