CVE-2025-55152 – Oak Denial of Service (DoS) Vulnerability

The following table lists the changes that have been made to the
CVE-2025-55152 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 09, 2025

    Action Type Old Value New Value
    Added Description oak is a middleware framework for Deno’s native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it’s possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Added CWE CWE-400
    Added CWE CWE-1333
    Added Reference https://github.com/oakserver/oak/commit/b60e60330ef227707c4dc13ef0ea36192d894f44
    Added Reference https://github.com/oakserver/oak/security/advisories/GHSA-r3v7-pc4g-7xp9
Share the Post:

Related Posts