Lucene search

K
nodejsCristian-Alexandru StaicuNODEJS:530
HistorySep 12, 2017 - 7:41 p.m.

Regular Expression Denial of Service

2017-09-1219:41:10
Cristian-Alexandru Staicu
www.npmjs.com
44

0.001 Low

EPSS

Percentile

44.7%

Overview

Affected versions of content are vulnerable to a regular expression denial of service when parsing malicious Content-Type and Content-Disposition headers.

Recommendation

Update to version 3.0.6 or later.

References

GitHub Advisory

CPENameOperatorVersion
contentle3.0.5

0.001 Low

EPSS

Percentile

44.7%