nodejs-debug: Regular expression Denial of Service
Published Jun 7, 2018
3.7
LOWCVSS 3.1
EPSS 2.88%
Description
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
Affected products
-
- Version <= 2.6.8 || >= 3.0.0 <= 3.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HackerOne | Debug Node Module | n/a |
|
- ≥ 2.0.0 · < 2.6.9
- ≥ 3.0.0 · < 3.1.0
No data.
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Mobile Application Platform 4
rhmap-fh-appstore-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-mbaas-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-messaging-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-metrics-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-ngui-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-scm-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-statsd-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap-fh-supercore-docker
Not affected
Red Hat Mobile Application Platform 4
rhmap45/fh-aaa
Not affected
Red Hat OpenShift Enterprise 3
nodejs-debug
Will not fix
Red Hat Software Collections
rh-nodejs4-nodejs-debug
Will not fix
Red Hat Software Collections
rh-nodejs6-nodejs-debug
Will not fix
Red Hat Software Collections
rh-nodejs8-nodejs-debug
Will not fix
Red Hat Virtualization 4
ovirt-engine-api-explorer
Out of support scope
Red Hat Virtualization 4
ovirt-engine-dashboard
Not affected
Red Hat Virtualization 4
ovirt-engine-ui-extensions
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Mobile Application Platform 4 | rhmap-fh-appstore-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-mbaas-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-messaging-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-metrics-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-ngui-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-scm-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-statsd-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap-fh-supercore-docker | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | rhmap45/fh-aaa | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | nodejs-debug | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs4-nodejs-debug | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs-debug | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs-debug | Will not fix | n/a |
| Red Hat Virtualization 4 | ovirt-engine-api-explorer | Out of support scope | n/a |
| Red Hat Virtualization 4 | ovirt-engine-dashboard | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | n/a |
debug
npm
Introduced 0 Fixed 2.6.9debug
npm
Introduced 3.0.0 Fixed 3.1.0debug
npm
Introduced 3.2.0 Fixed 3.2.7debug
npm
Introduced 4.0.0 Fixed 4.3.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | debug | 0 | 2.6.9 |
| npm | debug | 3.0.0 | 3.1.0 |
| npm | debug | 3.2.0 | 3.2.7 |
| npm | debug | 4.0.0 | 4.3.1 |
Remediation
Red Hat statement
This issue affects the versions of rh-nodejs4-nodejs-debug, rh-nodejs6-nodejs-debug, and rh-nodejs8-nodejs-debug as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Red Hat Virtualization 4.2 EUS includes a vulnerable version of nodejs-debug as a part of the ovirt-engine-api-explorer package. This package is removed in Red Hat Virtualization 4.3. Red Hat Quay includes the debug library as a dependency of karma-webpack. It is only used at build time, and not runtime so its impact is reduce to low in Red Hat Quay.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.88% (0.02876) | 86.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.77% (0.02775) | 84.44th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00080) | 21.23th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.30% (0.00296) | 70.13th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.30% (0.00296) | 68.46th | v3 (v2023.03.01) |
| Oct 28, 2023 | 0.30% (0.00296) | 65.87th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.32% (0.00321) | 66.53th | v3 (v2023.03.01) |
| May 31, 2023 | 0.22% (0.00225) | 59.39th | v3 (v2023.03.01) |
| May 8, 2023 | 0.18% (0.00177) | 53.33th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.25% (0.00253) | 61.32th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.55% (0.01550) | 33.66th | v1 |
| Jan 6, 2022 | 1.55% (0.01550) | 32.96th | v1 |
| Sep 1, 2021 | 1.55% (0.01550) | 73.01th | v1 |
| Apr 14, 2021 | 1.55% (0.01550) | 0.00th | v1 |
References (17)
- https://access.redhat.com/security/cve/CVE-2017-16137 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500705 Issue Tracking
- https://github.com/advisories/GHSA-gxpj-cx7g-858c Advisory
- https://github.com/debug-js/debug/commit/4e2150207c568adb9ead8f4c4528016081c88020
- https://github.com/debug-js/debug/commit/71169065b5262f9858ac78cc0b688c84a438f290
- https://github.com/debug-js/debug/commit/b6d12fdbc63b483e5c969da33ea6adc09946b5ac
- https://github.com/debug-js/debug/commit/f53962e944a87e6ca9bb622a2a12dffc22a9bb5a
- https://github.com/debug-js/debug/issues/797
- https://github.com/visionmedia/debug/issues/501 x_refsource_MISCThird Party Advisory
- https://github.com/visionmedia/debug/pull/504 x_refsource_MISCPatchThird Party Advisory
- https://lists.apache.org/thread.html/r8ba4c628fba7181af58817d452119481adce4ba92e889c643e4c7dd3%40%3Ccommits.netbeans.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8ba4c628fba7181af58817d452119481adce4ba92e889c643e4c7dd3@%3Ccommits.netbeans.apache.org%3E
- https://lists.apache.org/thread.html/rb5ac16fad337d1f3bb7079549f97d8166d0ef3082629417c39f12d63%40%3Cnotifications.netbeans.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb5ac16fad337d1f3bb7079549f97d8166d0ef3082629417c39f12d63@%3Cnotifications.netbeans.apache.org%3E
- https://nodesecurity.io/advisories/534 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-16137
- https://www.cve.org/CVERecord?id=CVE-2017-16137
Change history (0)
No recorded changes yet.