http-cache-semantics vulnerable to Regular Expression Denial of Service
- Severity:
- High
Description
http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Recommendation
Update the http-cache-semantics package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.1
- Patched version(s): 4.1.1
References
Related Issues
- steal vulnerable to Regular Expression Denial of Service via input variable - CVE-2022-37260
- steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments - CVE-2022-37262
- angular vulnerable to regular expression denial of service (ReDoS) - CVE-2022-25844
- es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens` - CVE-2024-27088
You might also like:
- Tags:
- npm
- http-cache-semantics
Anything's wrong? Let us know Last updated on February 13, 2025


