PoC Index

CVE-2017-16117

HIGH 7.5EPSS 1.6%

slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.

CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
1.58% chance of exploitation in the next 30 days, 74th percentile
Published
2018-06-07
Updated
2024-09-17

Proof-of-concept exploits (1)

References

Related