Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77082

Опубликовано: 20 авг. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pattern can block the worker for an extended period per data item processed, delaying other workflow executions on the same worker.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 1.123.69 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия от 2.0.0 (включая) до 2.33.4 (исключая)
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*

EPSS

Процентиль: 21%
0.00287
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 4.3
github
около 1 месяца назад

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pattern can block the worker for an extended period per data item processed, delaying other workflow executions on the same worker.

EPSS

Процентиль: 21%
0.00287
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1333