Intel

AIKIDO-2026-10024

@node-red/nodes is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 12, 2026

20

Low Risk

This Affects:

JS@node-red/nodes
0.0.1 - 4.1.2
Fixed in 4.1.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a crash due to uncaught exceptions in the Node-RED HTTP request node. Malformed responses or invalid server data can trigger errors such as a typo in toLowerCase(), missing error handling in request/redirect/response hooks, and insufficient input validation in cookie extraction and digest header construction, causing the entire Node-RED runtime to terminate.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@node-red/nodes is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 4.1.2.

How to fix this

Upgrade the @node-red/nodes library to the patch version.