Affected Node.js releases use a HashTable seed that is constant within a given released version. V8 snapshots, enabled by default during builds, overwrite the initially randomized seed at startup. This makes affected releases susceptible to remote hash-flooding denial-of-service attacks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small JavaScript/Node.js proof-of-concept set focused on Node.js security flaws, primarily CVE-2017-11499. It contains multiple standalone scripts rather than a polished exploit framework. The main files are: exploit.js, which combines three demonstrations (numeric auth misuse against http://127.0.0.1:8180, a simplistic timing-based object insertion test, and repeated malformed requests); poc.js, a minimal advisory-style reproduction of the numeric auth issue; real-hash-flooding-poc.js, a more complete hash-flooding DoS demonstration that generates many crafted keys, benchmarks collision behavior locally, and sends a large POST request to localhost:8180/api/process; and vuln-server.js / vuln-server2.js, which are local demo servers intended to simulate vulnerable behavior for testing. The exploit capability is primarily denial of service and vulnerability demonstration, not code execution. One branch of the repo targets the Node.js numeric auth/uninitialized buffer behavior in v4.x by setting opts.auth to a number before calling http.get(). The other branch targets predictable hash seed / hash flooding behavior by constructing large attacker-controlled objects and measuring or inducing slow processing. The POST attack in real-hash-flooding-poc.js is the clearest network exploit path: it sends a JSON body with 50,000 crafted keys to /api/process and judges success by server-side processing time. Repository structure is straightforward: README.md documents the two Node.js flaws; .nvmrc pins Node v8.0.0 for testing context; exploit and PoC scripts are in plain JavaScript with no dependencies beyond built-in Node modules; and the included servers provide a local lab environment on port 8180. Overall, this is an operational PoC repository for local or lab validation of Node.js denial-of-service-related flaws, with hardcoded localhost targets and no evidence of stealth, persistence, or post-exploitation features.
This repository is a small JavaScript proof-of-concept set for Node.js security flaws centered on CVE-2017-11499, though it mixes two related demonstrations: a numeric auth/http.get() bug and a hash-flooding denial-of-service scenario. It is not part of a known exploit framework. Repository structure: README.md documents the vulnerabilities and affected Node.js lines; exploit.js is the main multi-step demonstration script; poc.js is a minimal reproduction of the numeric auth issue; real-hash-flooding-poc.js is the more complete DoS-oriented script that generates many collision-style keys and POSTs them to a local endpoint; vuln-server.js and vuln-server2.js are local test servers used to simulate vulnerable behavior on port 8180. Main exploit capabilities: exploit.js sends requests to http://127.0.0.1:8180 with opts.auth set to numeric values, attempting to trigger the vulnerable handling path or observe patched TypeError behavior. It also includes a simplistic local object-insertion timing test and repeated requests intended to stress memory/request handling. real-hash-flooding-poc.js generates large numbers of crafted keys, builds a large JSON object, and sends it via POST to /api/process on localhost:8180 to measure processing delay and demonstrate potential CPU-exhaustion/DoS. The included servers accept requests and process attacker-controlled data to support local testing. Notable limitations: the code is primarily PoC/demo quality rather than a polished weaponized exploit. The hash-collision generation is heuristic and educational, not guaranteed to produce true collisions across all runtimes. real-hash-flooding-poc.js also references server.close() without defining server in that file, indicating some incompleteness. Overall, this is a functional local demonstration repository for vulnerable Node.js versions, with emphasis on denial-of-service testing and vulnerability verification rather than post-exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.