VDB
Sign up
MEDIUM5.3

GHSA-jc97-h3h9-7xh6

Regular Expression Denial of Service in Deno.upgradeWebSocket API

Details

### Impact Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

### Patches It is recommended that users upgrade to Deno 1.31.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/deno
Introduced in: 1.12.0Fixed in: 1.31.0

Upgrade deno to 1.31.0 or newer (ecosystem crates.io).

References