CVE-2020-27543
JavaScript vulnerability analysis and mitigation

Overview

The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exception. The vulnerability was discovered in November 2020 and affects version 0.0.5 of the package which had approximately 2,183 weekly downloads and at least 150,000 total downloads since release (GITHUB_SECOATS).

Technical details

The vulnerability occurs when the package is used as middleware and gets executed on every HTTP request to an endpoint. Any HTTP request without the HTTP Host-header sent to any existing API endpoint will cause the server to crash due to an uncaught exception in the middleware. The issue affects all endpoints regardless of whether the pagination feature is actually used. The exception is not caught by the standard restify error handler 'restify-errors'. The vulnerability has a CVSS v3.1 base score of 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) (NVD, NETAPP_ADVISORY).

Impact

Successful exploitation of this vulnerability could lead to Denial of Service (DoS) by causing the Node.js server instance to crash. The vulnerability affects any endpoint on the server where the middleware is implemented, making it a significant availability risk (NETAPP_ADVISORY).

Exploitability

The vulnerability is easily exploitable by sending a valid HTTP/1.0 request without a Host header to any existing API endpoint. While the Host header is technically required for HTTP/1.1, neither Node.js nor Restify reject requests missing this header. A proof of concept exploit has been published demonstrating the vulnerability (GITHUB_SECOATS).

Mitigation and workarounds

A quick fix for users of restify-paginate is setting hostname: false in the paginate() options. This hostname option is set to true by default. Disabling that option appears to skip over the affected code segment (GITHUB_SECOATS).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54504HIGH8.8
  • JavaScript logoJavaScript
  • @andrea9293/mcp-documentation-server
NoYesSep 17, 2026
CVE-2026-77615HIGH8.7
  • JavaScript logoJavaScript
  • paella-core
NoYesSep 17, 2026
CVE-2026-91127HIGH8.2
  • JavaScript logoJavaScript
  • @file-viewer/doc
NoYesSep 18, 2026
CVE-2026-77301HIGH7.5
  • JavaScript logoJavaScript
  • adm-zip
NoYesSep 18, 2026
CVE-2026-84992MEDIUM6.1
  • JavaScript logoJavaScript
  • md-editor-v3
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management