anchorme 在 3.0.8 及更早版本中存在正则表达式拒绝服务漏洞,该漏洞位于 IPv6 主机提取的正则表达式中,原因是发生了灾难性回溯。攻击者可以提供具有重复模式的精心构造的输入字符串,导致指数级正则表达式引擎回溯,从而阻塞 Node.js 事件循环并导致其他请求的服务不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet