{"id":"CVE-2023-38504","aliases":["GHSA-gpw9-fwm8-7rx7"],"url":"https://o3.security/vulnerability/CVE-2023-38504","summary":"Sails DoS vulnerability for apps with sockets enabled","details":"### Impact\nIn Sails apps <=v1.5.6, an attacker can send a virtual request that will cause the node process to crash. \n\n### Patches\nThis behavior was fixed in Sails [v1.5.7](https://github.com/balderdashy/sails/releases/tag/v1.5.7)\n\n### Workarounds\nDisable the sockets hook and remove the `sails.io.js` client\n\n### References\nhttps://github.com/balderdashy/sails/pull/7287\n\nBig thanks to @ThomasRinsma at [Codean](https://www.linkedin.com/company/codeanio/)!","published":"2023-07-27T18:12:05.419Z","modified":"2026-08-12T03:51:40.714476489Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"sails","fixedVersion":"1.5.7"}],"fix":{"url":"https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d","label":"balderdashy/sails@4a023dc"},"references":[{"type":"WEB","url":"https://github.com/balderdashy/sails/releases/tag/v1.5.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38504.json"},{"type":"ADVISORY","url":"https://github.com/balderdashy/sails/security/advisories/GHSA-gpw9-fwm8-7rx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38504"},{"type":"FIX","url":"https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d"},{"type":"FIX","url":"https://github.com/balderdashy/sails/pull/7287"},{"type":"PACKAGE","url":"https://github.com/balderdashy/sails"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.714476489Z"}}