ZeroHour

CVE-2022-25901

PoC ×2
CVSS 3.1
7.5 high
EPSS
2%p74
Published
()
Modified
Description

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

Vendors
cookiejar project
Products
cookiejar
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.