http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability
Published Jan 31, 2023
7.5
HIGHCVSS 3.1
EPSS 1.61%
Description
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Affected products
- Vendor n/a Product Org.webjars.npm:http-Cache-Semantics Defaultn/a
- Version 0StatusaffectedConstraints<4.1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Org.webjars.npm:http-Cache-Semantics | n/a |
|
- < 4.1.1
No data.
RHINT Service Registry 2.4.3 GA
http-cache-semantics
Fixed · RHSA-2023:3815
Red Hat Enterprise Linux 8
nodejs:14-8070020230306170042.bd1311ed
Fixed · RHSA-2023:1743
Red Hat Enterprise Linux 8
nodejs:16-8070020230314140722.bd1311ed
Fixed · RHSA-2023:1582
Red Hat Enterprise Linux 8
nodejs:18-8070020230322080930.bd1311ed
Fixed · RHSA-2023:1583
Red Hat Enterprise Linux 8.4 Extended Update Support
nodejs:14-8040020230306170312.522a0ee4
Fixed · RHSA-2023:1533
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:14-8060020230306170237.ad008a3a
Fixed · RHSA-2023:1742
Red Hat Enterprise Linux 9
nodejs-1:16.19.1-1.el9_2
Fixed · RHSA-2023:2655
Red Hat Enterprise Linux 9
nodejs:18-9020020230327152102.rhel9
Fixed · RHSA-2023:2654
Red Hat Enterprise Linux 9.0 Extended Update Support
nodejs-1:16.20.2-1.el9_0
Fixed · RHSA-2023:5533
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.8-5
Fixed · RHSA-2023:1428
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-0:3.6-2.el7
Fixed · RHSA-2023:1744
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.21.3-2.el7
Fixed · RHSA-2023:1744
.NET 6.0 on Red Hat Enterprise Linux
rh-dotnet60-dotnet
Out of support scope
Migration Toolkit for Virtualization
migration-toolkit-virtualization/mtv-ui-rhel8
Affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Affected
OpenShift Service Mesh 2.1
openshift-service-mesh/kiali-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-api-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-central-db-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-docs-rhel8
Will not fix
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Will not fix
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-rhel8-operator
Will not fix
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-roxctl-rhel8
Will not fix
Red Hat Decision Manager 7
http-cache-semantics
Not affected
Red Hat Discovery 1
discovery-server-container
Affected
Red Hat Enterprise Linux 8
cockpit
Not affected
Red Hat Enterprise Linux 8
cockpit-appstream
Not affected
Red Hat Enterprise Linux 8
container-tools:rhel8/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
dotnet6.0
Will not fix
Red Hat Enterprise Linux 9
dotnet6.0
Will not fix
Red Hat Fuse 7
http-cache-semantics
Out of support scope
Red Hat Integration Camel K 1
http-cache-semantics
Not affected
Red Hat JBoss Data Grid 7
http-cache-semantics
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
http-cache-semantics
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
http-cache-semantics
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
http-cache-semantics
Not affected
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Out of support scope
Red Hat OpenShift Dev Spaces
devspaces-theia-endpoint-rhel8-container
Out of support scope
Red Hat OpenShift Dev Spaces
devspaces-theia-rhel8-container
Out of support scope
Red Hat OpenShift Dev Spaces
devspaces/code-rhel8
Affected
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel8
Affected
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-all-in-one-rhel8
Affected
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-query-rhel8
Affected
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Out of support scope
Red Hat Openshift Data Foundation 4
noobaa-core-container
Affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Affected
Red Hat Single Sign-On 7
http-cache-semantics
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHINT Service Registry 2.4.3 GA | http-cache-semantics | Fixed | RHSA-2023:3815 |
| Red Hat Enterprise Linux 8 | nodejs:14-8070020230306170042.bd1311ed | Fixed | RHSA-2023:1743 |
| Red Hat Enterprise Linux 8 | nodejs:16-8070020230314140722.bd1311ed | Fixed | RHSA-2023:1582 |
| Red Hat Enterprise Linux 8 | nodejs:18-8070020230322080930.bd1311ed | Fixed | RHSA-2023:1583 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs:14-8040020230306170312.522a0ee4 | Fixed | RHSA-2023:1533 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:14-8060020230306170237.ad008a3a | Fixed | RHSA-2023:1742 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.19.1-1.el9_2 | Fixed | RHSA-2023:2655 |
| Red Hat Enterprise Linux 9 | nodejs:18-9020020230327152102.rhel9 | Fixed | RHSA-2023:2654 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | nodejs-1:16.20.2-1.el9_0 | Fixed | RHSA-2023:5533 |
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.8-5 | Fixed | RHSA-2023:1428 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-0:3.6-2.el7 | Fixed | RHSA-2023:1744 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.21.3-2.el7 | Fixed | RHSA-2023:1744 |
| .NET 6.0 on Red Hat Enterprise Linux | rh-dotnet60-dotnet | Out of support scope | n/a |
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-central-db-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-docs-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-rhel8-operator | Will not fix | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-roxctl-rhel8 | Will not fix | n/a |
| Red Hat Decision Manager 7 | http-cache-semantics | Not affected | n/a |
| Red Hat Discovery 1 | discovery-server-container | Affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-appstream | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet6.0 | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | dotnet6.0 | Will not fix | n/a |
| Red Hat Fuse 7 | http-cache-semantics | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | http-cache-semantics | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | http-cache-semantics | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | http-cache-semantics | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | http-cache-semantics | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | http-cache-semantics | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Out of support scope | n/a |
| Red Hat OpenShift Dev Spaces | devspaces-theia-endpoint-rhel8-container | Out of support scope | n/a |
| Red Hat OpenShift Dev Spaces | devspaces-theia-rhel8-container | Out of support scope | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel8 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Affected | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-all-in-one-rhel8 | Affected | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-query-rhel8 | Affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | noobaa-core-container | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Affected | n/a |
| Red Hat Single Sign-On 7 | http-cache-semantics | Not affected | n/a |
org.webjars.npm:http-cache-semantics
Maven
Introduced 0 Fixed 4.1.1http-cache-semantics
npm
Introduced 0 Fixed 4.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Maven | org.webjars.npm:http-cache-semantics | 0 | 4.1.1 |
| npm | http-cache-semantics | 0 | 4.1.1 |
Remediation
Red Hat statement
The impact of a succesfull exploiation of this vulnerability will only lead to a denial of service of the system,furthermore the exploitation will require an attacker to specifically craft a regular expression patterns in request headers (i.e. nontrivial input) that trigger pathological regex behavior but since most systems will have limits on header sizes or input validation that reduce the risk of triggering the extreme pathological regex cases which is why this has been marked as moderate.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 27, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.61% (0.01613) | 75.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.61% (0.01613) | 72.75th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.16% (0.00159) | 37.27th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.88% (0.01880) | 81.68th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.12% (0.00116) | 27.15th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.54% (0.07539) | 86.09th | v4 (v2025.03.14) |
| Mar 28, 2025 | 0.12% (0.00116) | 27.21th | v4 (v2025.03.14) |
| Mar 27, 2025 | 1.39% (0.01386) | 78.05th | v4 (v2025.03.14) |
| Mar 25, 2025 | 0.12% (0.00116) | 27.10th | v4 (v2025.03.14) |
| Mar 23, 2025 | 1.39% (0.01386) | 76.42th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.12% (0.00116) | 27.84th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.19% (0.00194) | 58.26th | v3 (v2023.03.01) |
| Jul 13, 2024 | 0.12% (0.00116) | 45.88th | v3 (v2023.03.01) |
| Mar 4, 2024 | 0.10% (0.00105) | 41.74th | v3 (v2023.03.01) |
| Feb 7, 2024 | 0.09% (0.00094) | 39.24th | v3 (v2023.03.01) |
| Jan 1, 2024 | 0.06% (0.00059) | 23.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00049) | 16.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Jan 31, 2023 | 0.95% (0.00954) | 35.75th | v2 (v2022.01.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2022-25881 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2165824 Issue Tracking
- https://github.com/advisories/GHSA-rc47-6667-2j5j Advisory
- https://github.com/kornelski/http-cache-semantics/blob/master/index.js%23L83 Broken Link
- https://github.com/kornelski/http-cache-semantics/commit/560b2d8ef452bbba20ffed69dc155d63ac757b74
- https://nvd.nist.gov/vuln/detail/CVE-2022-25881
- https://security.netapp.com/advisory/ntap-20230622-0008
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3253332 ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-HTTPCACHESEMANTICS-3248783 ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25881
Change history (0)
No recorded changes yet.