Количество 8
Количество 8
GHSA-g6wq-qcwm-j5g2
Regular Expression Denial of Service in websocket-extensions (RubyGem)

CVE-2020-7663
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVE-2020-7663
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVE-2020-7663
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
CVE-2020-7663
websocket-extensions ruby module prior to 0.1.5 allows Denial of Servi ...

SUSE-SU-2023:0127-1
Security update for rubygem-websocket-extensions

ROS-20250724-06
Уязвимость rubygem-websocket-extensions

BDU:2025-09009
Уязвимость модуля websocket-extensions языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-g6wq-qcwm-j5g2 Regular Expression Denial of Service in websocket-extensions (RubyGem) | CVSS3: 8.2 | 1% Низкий | около 5 лет назад | |
![]() | CVE-2020-7663 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад |
![]() | CVE-2020-7663 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад |
![]() | CVE-2020-7663 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад |
CVE-2020-7663 websocket-extensions ruby module prior to 0.1.5 allows Denial of Servi ... | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
![]() | SUSE-SU-2023:0127-1 Security update for rubygem-websocket-extensions | 1% Низкий | больше 2 лет назад | |
![]() | ROS-20250724-06 Уязвимость rubygem-websocket-extensions | CVSS3: 7.5 | 1% Низкий | 28 дней назад |
![]() | BDU:2025-09009 Уязвимость модуля websocket-extensions языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | около 5 лет назад |
Уязвимостей на страницу