Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25562
HistoryJun 03, 2020 - 2:15 a.m.

Regular Expression Denial Of Service (ReDoS)

2020-06-0302:15:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.002

Percentile

60.0%

websocket-extensions is vulnerable to regular expression denial of service (ReDoS). A regex backtracking is introduced due to the way the parser processes the Sec-WebSocket-Extensions header, using up quadratic time in a single-threaded server when an unclosed string parameter with repeating two-byte sequence of a backslash and some other character are included in the Sec-WebSocket-Extensions header.