René's URL Explorer Experiment


Title: V10.17.0 proposal by BethGriggs · Pull Request #29150 · nodejs/node · GitHub

Open Graph Title: V10.17.0 proposal by BethGriggs · Pull Request #29150 · nodejs/node

X Title: V10.17.0 proposal by BethGriggs · Pull Request #29150 · nodejs/node

Description: 2019-08-15, Version 10.17.0 'Dubnium' (LTS), @BethGriggs Notable changes This is a security release. Node.js, as well as many other implementations of HTTP/2, have been found vulnerable to Denial of Service attacks. See https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md for more information. Vulnerabilities fixed: CVE-2019-9511 “Data Dribble”: The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both, potentially leading to a denial of service. CVE-2019-9512 “Ping Flood”: The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both, potentially leading to a denial of service. CVE-2019-9513 “Resource Loop”: The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU, potentially leading to a denial of service. CVE-2019-9514 “Reset Flood”: The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both, potentially leading to a denial of service. CVE-2019-9515 “Settings Flood”: The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both, potentially leading to a denial of service. CVE-2019-9516 “0-Length Headers Leak”: The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory, potentially leading to a denial of service. CVE-2019-9517 “Internal Data Buffering”: The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both, potentially leading to a denial of service. CVE-2019-9518 “Empty Frames Flood”: The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU, potentially leading to a denial of service. (Discovered by Piotr Sikora of Google) Commits [74507fae34] - deps: update nghttp2 to 1.39.2 (Anna Henningsen) #29122 [a397c881ec] - deps: update nghttp2 to 1.39.1 (gengjiawen) #28448 [fedfa12a33] - deps: update nghttp2 to 1.38.0 (gengjiawen) #27295 [ab0f2ace36] - (SEMVER-MINOR) deps: update nghttp2 to 1.37.0 (gengjiawen) #26990 [0acbe05ee2] - http2: allow security revert for Ping/Settings Flood (Anna Henningsen) #29122 [c152449012] - http2: pause input processing if sending output (Anna Henningsen) #29122 [0ce699c7b1] - http2: stop reading from socket if writes are in progress (Anna Henningsen) #29122 [17357d37a9] - http2: consider 0-length non-end DATA frames an error (Anna Henningsen) #29122 [460f896c63] - http2: shrink default vector::reserve() allocations (Anna Henningsen) #29122 [f4242e24f9] - http2: handle 0-length headers better (Anna Henningsen) #29122 [477461a51f] - http2: limit number of invalid incoming frames (Anna Henningsen) #29122 [05dada46ee] - http2: limit number of rejected stream openings (Anna Henningsen) #29122 [7f11465572] - http2: do not create ArrayBuffers when no DATA received (Anna Henningsen) #29122 [2eb914ff5f] - http2: only call into JS when necessary for session events (Anna Henningsen) #29122 [76a7ada15d] - http2: improve JS-side debug logging (Anna Henningsen) #29122 [00f153da13] - http2: improve http2 code a bit (James M Snell) #23984 [a0a14c809f] - src: pass along errors from http2 object creation (Anna Henningsen) #25822 [d85e4006ab] - test: apply test-http2-max-session-memory-leak from v12.x (Anna Henningsen) #29122

Open Graph Description: 2019-08-15, Version 10.17.0 'Dubnium' (LTS), @BethGriggs Notable changes This is a security release. Node.js, as well as many other implementations of HTTP/2, have been found vulnerable to ...

X Description: 2019-08-15, Version 10.17.0 'Dubnium' (LTS), @BethGriggs Notable changes This is a security release. Node.js, as well as many other implementations of HTTP/2, have been found vulner...

Opengraph URL: https://github.com/nodejs/node/pull/29150

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository/pull/:id/commits/:range(.:format)
route-controllerpull_requests
route-actioncommits
fetch-noncev2:583339a1-814c-6392-905e-2ed5f8e4011f
current-catalog-service-hashae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b
request-id95A6:1B5A84:35BA5D7:47BFA88:6A65589A
html-safe-nonce89908a68b694d8f0dee6ba62d19b8b8792856982145587fe05a0c953e8e5415e
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5NUE2OjFCNUE4NDozNUJBNUQ3OjQ3QkZBODg6NkE2NTU4OUEiLCJ2aXNpdG9yX2lkIjoiNjI0MDQ0NTc3OTAxNzAyOTc4NiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmac26998bccbdd306688eb8f18b5a257d32d87ea5282d3eeefbf3f2ae16546a86d0
hovercard-subject-tagpull_request:307792601
github-keyboard-shortcutsrepository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///pull_requests/show/commits
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
twitter:imagehttps://avatars.githubusercontent.com/u/8297234?s=400&v=4
twitter:cardsummary_large_image
og:imagehttps://avatars.githubusercontent.com/u/8297234?s=400&v=4
og:image:alt2019-08-15, Version 10.17.0 'Dubnium' (LTS), @BethGriggs Notable changes This is a security release. Node.js, as well as many other implementations of HTTP/2, have been found vulnerable to ...
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None52c76df668885aaff23b50bdca1fa1ea44ac9c1553e888ebc70ff1e4daa4625b
turbo-cache-controlno-preview
diff-viewunified
go-importgithub.com/nodejs/node git https://github.com/nodejs/node.git
octolytics-dimension-user_id9950313
octolytics-dimension-user_loginnodejs
octolytics-dimension-repository_id27193779
octolytics-dimension-repository_nwonodejs/node
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id27193779
octolytics-dimension-repository_network_root_nwonodejs/node
turbo-body-classeslogged-out env-production page-responsive full-width
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release309153364422b3c499922d1a2a6404910a58ed8e
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fnodejs%2Fnode%2Fpull%2F29150%2Fcommits%2Ffedfa12a33bc81fec62ba6a6e0bba0b788ace38a
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub Copilot appDirect agents from issue to mergehttps://github.com/features/ai/github-app
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
Code QualityEnforce quality at mergehttps://github.com/features/code-quality
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
View all resourceshttps://github.com/resources
GitHub SponsorsFund open source developershttps://github.com/open-source/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/open-source/accelerator
GitHub Starshttps://stars.github.com
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/enterprise/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fnodejs%2Fnode%2Fpull%2F29150%2Fcommits%2Ffedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fpull_requests%2Fshow%2Fcommits&source=header-repo&source_repo=nodejs%2Fnode
Reloadhttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Reloadhttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Reloadhttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
nodejs https://github.com/nodejs
nodehttps://github.com/nodejs/node
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Notifications https://github.com/login?return_to=%2Fnodejs%2Fnode
Fork 36.1k https://github.com/login?return_to=%2Fnodejs%2Fnode
Star 118k https://github.com/login?return_to=%2Fnodejs%2Fnode
Code https://github.com/nodejs/node
Issues 1.3k https://github.com/nodejs/node/issues
Pull requests 1.1k https://github.com/nodejs/node/pulls
Actions https://github.com/nodejs/node/actions
Projects https://github.com/nodejs/node/projects
Security and quality 0 https://github.com/nodejs/node/security
Insights https://github.com/nodejs/node/pulse
Code https://github.com/nodejs/node
Issues https://github.com/nodejs/node/issues
Pull requests https://github.com/nodejs/node/pulls
Actions https://github.com/nodejs/node/actions
Projects https://github.com/nodejs/node/projects
Security and quality https://github.com/nodejs/node/security
Insights https://github.com/nodejs/node/pulse
Sign up for GitHub https://github.com/signup?return_to=%2Fnodejs%2Fnode%2Fissues%2Fnew%2Fchoose
terms of servicehttps://docs.github.com/terms
privacy statementhttps://docs.github.com/privacy
Sign inhttps://github.com/login?return_to=%2Fnodejs%2Fnode%2Fissues%2Fnew%2Fchoose
BethGriggshttps://github.com/BethGriggs
v10.xhttps://github.com/nodejs/node/tree/v10.x
v10.17.0-proposalhttps://github.com/nodejs/node/tree/v10.17.0-proposal
Conversation 4 https://github.com/nodejs/node/pull/29150
Commits 19 https://github.com/nodejs/node/pull/29150/commits
Checks 0 https://github.com/nodejs/node/pull/29150/checks
Files changed https://github.com/nodejs/node/pull/29150/files
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
V10.17.0 proposal https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#top
Show all changes 19 commits https://github.com/nodejs/node/pull/29150/files
00f153d http2: improve http2 code a bit jasnell Oct 30, 2018 https://github.com/nodejs/node/pull/29150/commits/00f153da1352b941d8749758edb6083a6acda715
a0a14c8 src: pass along errors from http2 object creation addaleax Jan 30, 2019 https://github.com/nodejs/node/pull/29150/commits/a0a14c809ffe59146fa16284c2f3f84e3f8f02c7
ab0f2ac deps: update nghttp2 to 1.37.0 gengjiawen Mar 29, 2019 https://github.com/nodejs/node/pull/29150/commits/ab0f2ace36a116f1e905c17e61904cc48abd76c2
fedfa12 deps: update nghttp2 to 1.38.0 gengjiawen Apr 18, 2019 https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
a397c88 deps: update nghttp2 to 1.39.1 gengjiawen Jun 27, 2019 https://github.com/nodejs/node/pull/29150/commits/a397c881ecb13a47663ccbbfca4762dc044ee4d6
74507fa deps: update nghttp2 to 1.39.2 addaleax Aug 14, 2019 https://github.com/nodejs/node/pull/29150/commits/74507fae34deae8a0011b6bebf81a450de4ab8a9
76a7ada http2: improve JS-side debug logging addaleax Aug 5, 2019 https://github.com/nodejs/node/pull/29150/commits/76a7ada15d4cbad16bd3b48ad839843f2e089b9e
2eb914f http2: only call into JS when necessary for session events addaleax Aug 9, 2019 https://github.com/nodejs/node/pull/29150/commits/2eb914ff5f1f3ddcbe91c50c5b0ae3fe565e2bba
7f11465 http2: do not create ArrayBuffers when no DATA received addaleax Aug 9, 2019 https://github.com/nodejs/node/pull/29150/commits/7f11465572888340b4c7b399c1f46598d1c4ea50
05dada4 http2: limit number of rejected stream openings addaleax Aug 10, 2019 https://github.com/nodejs/node/pull/29150/commits/05dada46eea59c0bfdabe4f54d64cda2f315cec9
477461a http2: limit number of invalid incoming frames addaleax Aug 12, 2019 https://github.com/nodejs/node/pull/29150/commits/477461a51f64ec6969654d98018281b0ba2a5464
f4242e2 http2: handle 0-length headers better addaleax Aug 10, 2019 https://github.com/nodejs/node/pull/29150/commits/f4242e24f9f4fb185909f040cbd2dd889d79439b
460f896 http2: shrink default `vector::reserve()` allocations addaleax Aug 10, 2019 https://github.com/nodejs/node/pull/29150/commits/460f896c631f1be52b0ab6c9f30e0b66f601b2a1
17357d3 http2: consider 0-length non-end DATA frames an error addaleax Aug 10, 2019 https://github.com/nodejs/node/pull/29150/commits/17357d37a9eba4ac1cbafe8628bf12cc900bc642
0ce699c http2: stop reading from socket if writes are in progress addaleax Aug 10, 2019 https://github.com/nodejs/node/pull/29150/commits/0ce699c7b120ae7c672f4ffd0dc1562db3dae0a7
c152449 http2: pause input processing if sending output addaleax Aug 11, 2019 https://github.com/nodejs/node/pull/29150/commits/c152449012e21dbf1c3e8bd2081600b9f3858549
0acbe05 http2: allow security revert for Ping/Settings Flood addaleax Aug 12, 2019 https://github.com/nodejs/node/pull/29150/commits/0acbe05ee2d0e073e52cfe96a9e701dc9891a360
d85e400 test: apply test-http2-max-session-memory-leak from v12.x addaleax Aug 13, 2019 https://github.com/nodejs/node/pull/29150/commits/d85e4006ab931c656496a143f03473ebc69eea29
8994fff 2019-08-15, Version 10.17.0 'Dubnium' (LTS) BethGriggs Aug 15, 2019 https://github.com/nodejs/node/pull/29150/commits/8994fff6e695a35f298cc53827c64c0fd13b0bf9
Clear filters https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
nghttp2ver.h https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-331c68fdcc1b5246ebc20b8835147eaef6544b7930e2a124947ccf5d8c818d31
nghttp2_session.c https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-f53cfae036fa2d3406af4f16d324118593788a85eacfd41d0a7aaf3cc8b40dbe
Prev https://github.com/nodejs/node/pull/29150/commits/ab0f2ace36a116f1e905c17e61904cc48abd76c2
Next https://github.com/nodejs/node/pull/29150/commits/a397c881ecb13a47663ccbbfca4762dc044ee4d6
#29123https://github.com/nodejs/node/pull/29123
#27295https://github.com/nodejs/node/pull/27295
Please reload this pagehttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a
https://github.com/gengjiawen
https://github.com/BethGriggs
gengjiawenhttps://github.com/nodejs/node/commits?author=gengjiawen
BethGriggshttps://github.com/nodejs/node/commits?author=BethGriggs
deps/nghttp2/lib/includes/nghttp2/nghttp2ver.hhttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-331c68fdcc1b5246ebc20b8835147eaef6544b7930e2a124947ccf5d8c818d31
View file https://github.com/nodejs/node/blob/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a/deps/nghttp2/lib/includes/nghttp2/nghttp2ver.h
Open in desktop https://desktop.github.com
https://github.co/hiddenchars
https://github.com/nodejs/node/pull/29150/commits/{{ revealButtonHref }}
https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-331c68fdcc1b5246ebc20b8835147eaef6544b7930e2a124947ccf5d8c818d31
deps/nghttp2/lib/nghttp2_session.chttps://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-f53cfae036fa2d3406af4f16d324118593788a85eacfd41d0a7aaf3cc8b40dbe
View file https://github.com/nodejs/node/blob/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a/deps/nghttp2/lib/nghttp2_session.c
Open in desktop https://desktop.github.com
https://github.co/hiddenchars
https://github.com/nodejs/node/pull/29150/commits/{{ revealButtonHref }}
https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-f53cfae036fa2d3406af4f16d324118593788a85eacfd41d0a7aaf3cc8b40dbe
https://github.com/nodejs/node/pull/29150/commits/fedfa12a33bc81fec62ba6a6e0bba0b788ace38a#diff-f53cfae036fa2d3406af4f16d324118593788a85eacfd41d0a7aaf3cc8b40dbe
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.