Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39306
HistoryFeb 17, 2023 - 2:40 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-02-1702:40:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
undici
software
redos
vulnerability
headervaluenormalize
function
headers.js
insecure regex pattern

0.001 Low

EPSS

Percentile

48.5%

undici is vulnerable to Regular Expression Denial Of Service (ReDoS). The vulnerability exists due to an insecure Regex pattern used in the headerValueNormalize function in headers.js, which allows an attacker to crash the application by providing a malicious input.