Rewterz
Rewterz Threat Alert – STRRAT Malware – Active IOCs
February 28, 2023
Rewterz
Rewterz Threat Alert – IcedID Banking Trojan aka BokBot – Active IOCs
March 1, 2023

Rewterz Threat Advisory – CVE-2023-26105 – Node.js utilities module Vulnerability

Severity

High

Analysis Summary

CVE-2023-26105

Node.js utilities module is vulnerable to a denial of service, caused by a prototype pollution in the _mix function. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2023-26105

Affected Vendors

Node.js

Affected Products

  • Node.js utilities 1.0.6

Remediation

Refer to SNYK-JS-UTILITIES for patch, upgrade or suggested workaround information. 

SNYK-JS-UTILITIES