CVE-2016-10539
Last modified
CVE-2016-10539 is a vulnerability of currently unknown severity. negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Negotiator Project | Negotiator | <= 0.6.0 |
References
- https://nodesecurity.io/advisories/106Third Party Advisory
- https://nodesecurity.io/advisories/106Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10539?
How severe is CVE-2016-10539?
How do I fix CVE-2016-10539?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10533express-restify-mongoose is a module to easily create a flex…
- CVE-2016-10534electron-packager is a command line tool that packages Elect…
- CVE-2016-10535csrf-lite is a cross-site request forgery protection library…
- CVE-2016-10536engine.io-client is the client for engine.io, the implementa…
- CVE-2016-10537backbone is a module that adds in structure to a JavaScript …
- CVE-2016-10538The package `node-cli` before 1.0.0 insecurely uses the lock…
- CVE-2016-1054Use-after-free vulnerability in Adobe Reader and Acrobat bef…
- CVE-2016-10540Minimatch is a minimal matching utility that works by conver…
- CVE-2016-10541The npm module "shell-quote" 1.6.0 and earlier cannot correc…9.8
- CVE-2016-10542ws is a "simple to use, blazing fast and thoroughly tested w…
- CVE-2016-10543call is an HTTP router that is primarily used by the hapi fr…
- CVE-2016-10544uws is a WebSocket server library. By sending a 256mb websoc…
Are you affected by CVE-2016-10539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
