Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10539

Опубликовано: 31 мая 2018
Источник: debian
EPSS Низкий

Описание

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-negotiatorfixed0.6.1-1package

Примечания

  • https://nodesecurity.io/advisories/106

  • nodejs not covered by security support

EPSS

Процентиль: 55%
0.00328
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

CVSS3: 7.5
nvd
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

github
больше 7 лет назад

Regular Expression Denial of Service in negotiator

EPSS

Процентиль: 55%
0.00328
Низкий