CVE-2016-10539
Last modified
CVE-2016-10539 is a vulnerability of currently unknown severity. negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Negotiator Project | Negotiator | <= 0.6.0 |
References
- https://nodesecurity.io/advisories/106Third Party Advisory
- https://nodesecurity.io/advisories/106Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10539?
How severe is CVE-2016-10539?
How do I fix CVE-2016-10539?
Are you affected by CVE-2016-10539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
