Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55152

Опубликовано: 09 авг. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.

EPSS

Процентиль: 16%
0.00051
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
github
6 месяцев назад

Oak Server has ReDoS in x-forwarded-proto and x-forwarded-for headers

EPSS

Процентиль: 16%
0.00051
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400