Lucene search

K
cvelistSnykCVELIST:CVE-2020-7662
HistoryJun 02, 2020 - 6:28 p.m.

CVE-2020-7662

2020-06-0218:28:46
snyk
www.cve.org
6

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

60.0%

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CNA Affected

[
  {
    "product": "websocket-extensions (npm)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to 0.1.4"
      }
    ]
  }
]

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

60.0%