Vulnerabilities/

ReDoS via long string of semicolons in tough-cookie

Severity:
Medium

Description

Affected versions of tough-cookie may be vulnerable to regular expression denial of service when long strings of semicolons exist in the Set-Cookie header.

Recommendation

Update the tough-cookie package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tough-cookie
Anything's wrong? Let us know Last updated on April 11, 2023

This issue is available in SmartScanner Professional

See Pricing