{"id":"CVE-2023-38504","aliases":["GHSA-gpw9-fwm8-7rx7"],"url":"https://o3.security/vulnerability/CVE-2023-38504","summary":"Sails DoS vulnerability for apps with sockets enabled","details":"Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the `sails.io.js` client.","published":"2023-07-27T18:12:05.419Z","modified":"2026-07-15T01:49:00.887445118Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"sails","fixedVersion":"1.5.7"}],"fix":{"url":"https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d","label":"balderdashy/sails@4a023dc"},"references":[{"type":"WEB","url":"https://github.com/balderdashy/sails/releases/tag/v1.5.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38504.json"},{"type":"ADVISORY","url":"https://github.com/balderdashy/sails/security/advisories/GHSA-gpw9-fwm8-7rx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38504"},{"type":"FIX","url":"https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d"},{"type":"FIX","url":"https://github.com/balderdashy/sails/pull/7287"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:00.887445118Z"}}