CVE-2023-26108

All FrameworksNestJSCWE-200CVE-2023-26108

CVE-2023-26108

State: PUBLISHED · Published: 2023-03-06 · Updated: 2025-03-05 · Assigner: snyk
Description
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/26xxx/CVE-2023-26108.json