Vulnerability GHSA-rc47-6667-2j5j

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
January 31, 2023 at 06:30 AM UTC
http-cache-semantics vulnerable to Regular Expression Denial of Service
1.0.0 - 4.1.0
1.0.0 - 4.1.0

Summary

http-cache-semantics vulnerable to Regular Expression Denial of Service

Details

http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

Timeline

Published
3 years ago
January 31, 2023 at 06:30 AM UTC
Fixed (4.1.1)
Unknown
Unknown
Fixed (4.1.1)
Unknown
Unknown
Last Modified
22 days ago
September 10, 2026 at 03:49 AM UTC