Back

MEDIUM

nodejs-tough-cookie: regular expression DoS via Cookie header with many semicolons

Published Sep 5, 2018

Description

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 5, 2018
Updated Aug 6, 2024
Reserved Oct 28, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 22, 2016
GHSA-QHV9-728R-6JQG