Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-16129

5.9 · MEDIUM
Published Jun 7, 2018 superagent_project CWE-409 EPSS 1.77% (77th pctl)

Overview

CVE-2017-16129 is a medium-severity vulnerability affecting superagent_project superagent. It was published on June 7, 2018 and has a CVSS 3.0 base score of 5.9 (MEDIUM).

This vulnerability has a CVSS 3.0 base score of 5.9, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

Remediation

Check the references section for vendor advisories and patches from superagent_project. Update superagent to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
superagent_project superagent >= 0, < 3.7.0 Affected

Frequently Asked Questions

What is CVE-2017-16129?

CVE-2017-16129 is a medium-severity vulnerability affecting superagent_project superagent. It was published on June 7, 2018 and has a CVSS 3.0 base score of 5.9 (MEDIUM).

How severe is CVE-2017-16129?

This vulnerability has a CVSS 3.0 base score of 5.9, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2017-16129?

Check the references section for vendor advisories and patches from superagent_project. Update superagent to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-16129?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-16129 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.