Lucene search

K
osvGoogleOSV:GHSA-7MC5-CHHP-FMC3
HistoryOct 09, 2018 - 12:30 a.m.

Regular Expression Denial of Service in negotiator

2018-10-0900:30:30
Google
osv.dev
6

0.001 Low

EPSS

Percentile

44.7%

Affected versions of negotiator are vulnerable to regular expression denial of service attacks, which trigger upon parsing a specially crafted Accept-Language header value.

Recommendation

Update to version 0.6.1 or later.

CPENameOperatorVersion
negotiatorlt0.6.1

0.001 Low

EPSS

Percentile

44.7%