Description
A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0364 | A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string. |
Github GHSA |
GHSA-pm9p-9926-w68m | Denial of Service in ecstatic |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:30:20.174Z
Reserved: 2017-12-14T00:00:00.000Z
Link: CVE-2016-10703
No data.
Status : Modified
Published: 2017-12-14T19:29:00.197
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-10703
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA