Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
websocket-extensions 安全漏洞
Vulnerability Description
websocket-extensions是一款开源的WebSocket通用扩展管理器。 websocket-extensions(npm)1.0.4之前版本中存在安全漏洞。攻击者可借助Sec-WebSocket-Extensions标头利用该漏洞造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A