Back

HIGH

nodejs-tough-cookie: Regular expression denial of service

Published Oct 3, 2017

Description

A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.

Affected products

Remediation

Red Hat statement

Red Hat Quay include nodejs-tough-cookie as a build time dependency of protractor. It's no included in the runtime code, and is therefore not affected by this vulnerability.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 3, 2017
Updated Aug 5, 2024
Reserved Oct 3, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 5, 2017
GHSA-G7Q5-PJJR-GQVP