mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
- Severity:
- High
Description
Affected versions of mime are vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
Recommendation
Update the mime package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0, < 2.0.3 < 1.4.1** Patched version(s): **2.0.3 1.4.1**
References
Related Issues
- Regular Expression Denial of Service in slug - CVE-2017-16117
- Regular Expression Denial of Service in no-case - CVE-2017-16099
- Regular Expression Denial of Service in debug - CVE-2017-16137
- Regular Expression Denial of Service in parsejson - CVE-2017-16113
You might also like:
- Tags:
- npm
- mime
Anything's wrong? Let us know Last updated on September 12, 2023


