VDB
Sign up
HIGH7.5

GHSA-rc47-6667-2j5j

http-cache-semantics vulnerable to Regular Expression Denial of Service

Quick fix

GHSA-rc47-6667-2j5j — http-cache-semantics: upgrade to the fixed version with the command below.

npm install http-cache-semantics@4.1.1

Details

http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/http-cache-semantics
Introduced in: 0Fixed in: 4.1.1
Fixnpm install http-cache-semantics@4.1.1
Maven/org.webjars.npm:http-cache-semantics
Introduced in: 0Fixed in: 4.1.1
Fix# pom.xml: bump <version>4.1.1</version> for org.webjars.npm:http-cache-semantics

References