CVE-2018-7164
Status: ModifiedHigh (7.5)—
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 6.44%
- Percentile among all scored CVEs: 94
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-400
References
- http://www.securityfocus.com/bid/104463
- https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/
- https://security.gentoo.org/glsa/202003-48
- http://www.securityfocus.com/bid/104463
- https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/
- https://security.gentoo.org/glsa/202003-48
Raw JSON (NVD)
Show
{
"id": "CVE-2018-7164",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-request@iojs.org",
"affectedData": [
{
"vendor": "The Node.js Project",
"product": "Node.js",
"versions": [
{
"status": "affected",
"version": "9.7.X+"
},
{
"status": "affected",
"version": "10.x+"
}
]
}
]
}
],
"published": "2018-06-13T16:29:01.827",
"references": [
{
"url": "http://www.securityfocus.com/bid/104463",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve-request@iojs.org"
},
{
"url": "https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/",
"tags": [
"Vendor Advisory"
],
"source": "cve-request@iojs.org"
},
{
"url": "https://security.gentoo.org/glsa/202003-48",
"tags": [
"Third Party Advisory"
],
"source": "cve-request@iojs.org"
},
{
"url": "http://www.securityfocus.com/bid/104463",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/202003-48",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour."
},
{
"lang": "es",
"value": "Todas las versiones 9.7.0 y posteriores y 10.x de Node.js son vulnerables y la gravedad es MEDIA. Un error introducido en la versión 9.7.0 aumenta la memoria consumida cuando se lee desde la red en JavaScript mediante el uso del objeto net.Socket directamente como transmisión. Un atacante podría emplear esto para provocar una denegación de servicio (DoS) mediante el envío de fragmentos diminutos de datos en una sucesión corta. Esta vulnerabilidad se solucionó volviendo al comportamiento anterior."
}
],
"lastModified": "2026-06-17T02:02:43.607",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CE5845F-4758-41B7-B801-6785E22BDF94",
"versionEndExcluding": "9.11.2",
"versionStartIncluding": "9.7.0"
},
{
"criteria": "cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FF733A8-C8E5-4F47-8494-20D4AC10B1D0",
"versionEndExcluding": "10.4.1",
"versionStartIncluding": "10.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-request@iojs.org"
}