Description
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0315 | method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header. |
Github GHSA |
GHSA-qx2f-477c-35rq | method-override ReDoS when untrusted user input passed into X-HTTP-Method-Override header |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T03:18:13.960Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16136
No data.
Status : Modified
Published: 2018-06-07T02:29:03.770
Modified: 2024-11-21T03:15:53.580
Link: CVE-2017-16136
OpenCVE Enrichment
No data.
EUVD
Github GHSA