Back

HIGH

http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

Published Jan 31, 2023

Description

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

Affected products

Remediation

Red Hat statement

The impact of a succesfull exploiation of this vulnerability will only lead to a denial of service of the system,furthermore the exploitation will require an attacker to specifically craft a regular expression patterns in request headers (i.e. nontrivial input) that trigger pathological regex behavior but since most systems will have limits on header sizes or input validation that reduce the risk of triggering the extreme pathological regex cases which is why this has been marked as moderate.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jan 31, 2023
Updated Mar 27, 2025
Reserved Feb 24, 2022
CISA Vulnrichment
Updated Mar 27, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 31, 2023
GHSA-RC47-6667-2J5J