Back

HIGH

nodejs-no-case: regular expression denial of service in no-case module

Published Jun 7, 2018

Description

The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.

Affected products

Remediation

Red Hat statement

Red Hat Quay imports nodejs-no-case as a build time dependency of html-loader. Nodejs-no-case is only used as build time, and not at runtime.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jun 7, 2018
Updated Sep 17, 2024
Reserved Oct 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 6, 2018
GHSA-FF6R-5JWM-8292