Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30703
HistoryMay 27, 2021 - 5:47 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-05-2705:47:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
25
regular expression
denial of service
vulnerability
ws" software
cpu consumption
application crash
malicious value

EPSS

0.002

Percentile

60.7%

ws is vulnerable to regular expression denial of service. An attacker is able to cause excessive CPU consumption that can lead to an application crash by submitting a malicious value of Sec-Websocket-Protocol.