2018-12-03, Version 6.15.1 'Boron' (LTS), @rvagg
Notable Changes
This is a patch release to address a bad backport of the fix for "Slowloris HTTP Denial of Service" (CVE-2018-12122). Node.js 6.15.0 misapplies the headers timeout to an entire keep-alive HTTP session, resulting in prematurely disconnected sockets.
Commits
- [
5d9005c359
] - http: fix backport of Slowloris headers (Matteo Collina) #24796