Description
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0269 | A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU. |
Github GHSA |
GHSA-g7q5-pjjr-gqvp | Regular Expression Denial of Service in tough-cookie |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:42:22.357Z
Reserved: 2017-10-03T00:00:00.000Z
Link: CVE-2017-15010
No data.
Status : Modified
Published: 2017-10-04T01:29:03.403
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15010
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA