Lucene search

K
redhatcveRedhat.comRH:CVE-2020-7662
HistoryJul 18, 2021 - 1:58 a.m.

CVE-2020-7662

2021-07-1801:58:45
redhat.com
access.redhat.com
86
cve-2020-7662
denial of service
regex backtracking
redos
sec-websocket-extensions

EPSS

0.002

Percentile

60.0%

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.