Vulnerabilities/

http-cache-semantics vulnerable to Regular Expression Denial of Service

Severity:
High

Description

http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

Recommendation

Update the http-cache-semantics package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
http-cache-semantics
Anything's wrong? Let us know Last updated on February 13, 2025