{"id":"CVE-2023-30591","summary":"NodeBB Pre-Authentication Denial-of-Service","details":"Denial-of-service in NodeBB \u003c= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.","modified":"2026-08-12T03:51:27.173729587Z","published":"2023-09-29T05:06:43.923Z","database_specific":{"cna_assigner":"STAR_Labs","cwe_ids":["CWE-241"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30591.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30591.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30591"},{"type":"ADVISORY","url":"https://starlabs.sg/advisories/23/23-30591/"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/commit/37b48b82a4bc7680c6e4c42647209010cb239c2c"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/commit/4d2d76897a02e7068ab74c81d17a2febfae8bfb9"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/commit/830f142b7aea2e597294a84d52c05aab3a3539ca"},{"type":"PACKAGE","url":"https://github.com/NodeBB/NodeBB"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nodebb/nodebb","events":[{"introduced":"0"},{"fixed":"37b48b82a4bc7680c6e4c42647209010cb239c2c"},{"fixed":"4d2d76897a02e7068ab74c81d17a2febfae8bfb9"},{"fixed":"830f142b7aea2e597294a84d52c05aab3a3539ca"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.8.10"}]}}],"versions":["v2.8.10","v2.8.9","v2.8.8","v2.8.7","v2.8.6","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.8.0","v2.7.0","v2.6.1","v2.6.0","v2.4.0","v2.3.1","v2.3.0","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.1","v2.1.0","v2.0.1","v1.19.7","v1.19.6","v1.19.4","v1.17.0-beta.5","v1.17.0-beta.4","v1.17.0-beta.3","v1.17.0-beta.2","v1.17.0-beta.0","v1.16.1-beta.0","v1.15.3-beta.0","v1.15.2-beta.1","v1.15.2-beta.0","v1.15.1","v1.15.1-beta.0","v1.15.0","v1.15.0-rc.5","v1.15.0-rc.4","v1.15.0-rc.3","v1.15.0-rc.1","v1.15.0-rc.0","v1.15.0-beta.30","v1.15.0-beta.29","v1.15.0-beta.27","v1.15.0-beta.25","v1.15.0-beta.24","v1.15.0-beta.23","v1.15.0-beta.22","v1.15.0-beta.21","v1.15.0-beta.19","v1.15.0-beta.18","v1.15.0-beta.17","v1.15.0-beta.16","v1.15.0-beta.15","v1.15.0-beta.14","v1.15.0-beta.13","v1.15.0-beta.12","v1.15.0-beta.11","v1.15.0-beta.10","v1.15.0-beta.9","v1.15.0-beta.8","v1.15.0-beta.7","v1.15.0-beta.6","v1.15.0-beta.5","v1.15.0-beta.4","v1.15.0-beta.3","v1.15.0-beta.2","v1.15.0-beta.1","v1.15.0-beta.0","v1.14.3-beta.16","v1.14.3-beta.15","v1.14.3-beta.14","v1.14.3-beta.13","v1.14.3-beta.12","v1.14.3-beta.11","v1.14.3-beta.10","v1.14.3-beta.9","v1.14.3-beta.8","v1.14.3-beta.7","v1.14.3-beta.6","v1.14.3-beta.5","v1.14.3-beta.4","v1.14.3-beta.0","v1.14.2-beta.1","v1.14.1-beta.3","v1.14.1-beta.1","v1.14.1-beta.0","v1.5.3","v0.9.2","v0.5.0-2","v0.5.0-1","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.0.6","v0.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30591.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}