Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24026 | Oak Server has ReDoS in x-forwarded-proto and x-forwarded-for headers |
Github GHSA |
GHSA-r3v7-pc4g-7xp9 | Oak Server has ReDoS in x-forwarded-proto and x-forwarded-for headers |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oakserver
Oakserver oak |
|
| Vendors & Products |
Oakserver
Oakserver oak |
Mon, 11 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Title | oak: ReDoS in x-forwarded-proto and x-forwarded-for headers | |
| Weaknesses | CWE-1333 CWE-400 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-11T13:33:40.071Z
Reserved: 2025-08-07T18:27:23.305Z
Link: CVE-2025-55152
Updated: 2025-08-11T13:33:16.293Z
Status : Awaiting Analysis
Published: 2025-08-09T02:15:38.033
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-55152
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:13Z
EUVD
Github GHSA