Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36570
HistoryAug 02, 2022 - 3:12 p.m.

Regular Expression Denial Of Service (ReDoS)

2022-08-0215:12:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
node-fetch
redos
`referrer` field
regular expression complexity
denial of service

0.001 Low

EPSS

Percentile

37.9%

Node-fetch is vulnerable to denial of service. The vulnerability lies in the referrer field in the fetch() function, leading to inefficient Regular Expression Complexity. If an attacker is able to use a large character string in the referrer field, the program will either hang or crash.

CPENameOperatorVersion
node-fetchle3.2.9
node-fetchle3.2.9

0.001 Low

EPSS

Percentile

37.9%