Lucene search

K
osvGoogleOSV:GHSA-QHV9-728R-6JQG
HistoryOct 10, 2018 - 6:57 p.m.

ReDoS via long string of semicolons in tough-cookie

2018-10-1018:57:02
Google
osv.dev
15

EPSS

0.006

Percentile

79.2%

Affected versions of tough-cookie may be vulnerable to regular expression denial of service when long strings of semicolons exist in the Set-Cookie header.

Recommendation

Update to version 2.3.0 or later.