oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oakserver
Oakserver oak |
|
| Vendors & Products |
Oakserver
Oakserver oak |
Mon, 11 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Title | oak: ReDoS in x-forwarded-proto and x-forwarded-for headers | |
| Weaknesses | CWE-1333 CWE-400 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-09T01:29:54.545Z
Updated: 2025-08-11T13:33:40.071Z
Reserved: 2025-08-07T18:27:23.305Z
Link: CVE-2025-55152
Updated: 2025-08-11T13:33:16.293Z
Status : Awaiting Analysis
Published: 2025-08-09T02:15:38.033
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-55152
No data.