DirectorySecurity Advisories
Sign In
Security Advisories

CGA-92f2-wx89-q5ff

Published

Last updated

https://images.chainguard.dev/security/CGA-92f2-wx89-q5ff
Package

nodejs-14

Latest Update
Fixed
Fixed Version

14.21.3-r1

Aliases
  • CVE-2022-25881
  • GHSA-rc47-6667-2j5j

Severity

7.5

High

CVSS V3

Summary

http-cache-semantics vulnerable to Regular Expression Denial of Service

Description

http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images