Severity
Details
- CVSS score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Overview
About vulnerability
Impact
Remotely triggerable DoS in find-my-way when it is used with Node’s HTTP/2 server.
The short version is that lookup() passes req.method into find(), and find() indexes this.trees[method]. Since this.trees is a normal object, HTTP/2 method values like constructor, toString, or __proto__ can resolve inherited object properties instead of returning undefined. The code then treats that value like a router node and crashes when it reaches currentNode.prefix.length.
Patches
Upgrade to v9.7.0.
Workarounds
Do not use find-my-way with HTTP/2 servers, or validate that the http method is valid beforehand.
Details
- Affected product:
- Fastify , React , astro , db0 , devtools , drizzle-orm , find-my-way , nitro , nuxt , prisma , unstorage , vite , vite-dev-rpc , vite-hot-client , vite-plugin-checker , vite-plugin-inspect , vite-plugin-react , vite-plugin-vue , vite-plugin-vue-inspector , vite-plugin-vue-tracer , vitefu
- Affected packages:
- react-router-dev @ 7.5.1 (+90 more)