Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6260
HistoryMay 09, 2018 - 8:03 a.m.

Denial Of Service (DoS)

2018-05-0908:03:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.001

Percentile

49.1%

node is vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability exists in the path module of Node.js 4.x releases that contains a bad regex defined in splitPathRe that causes ReDoS attacks when parsing malicious paths.