oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oakserver
Oakserver oak |
|
Vendors & Products |
Oakserver
Oakserver oak |
Mon, 11 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Aug 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
Title | oak: ReDoS in x-forwarded-proto and x-forwarded-for headers | |
Weaknesses | CWE-1333 CWE-400 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-11T13:33:40.071Z
Reserved: 2025-08-07T18:27:23.305Z
Link: CVE-2025-55152

Updated: 2025-08-11T13:33:16.293Z

Status : Awaiting Analysis
Published: 2025-08-09T02:15:38.033
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-55152

No data.