Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-23490: Regular Expression Denial of Service (ReDoS) in parse-link-header | CVE-2021-23490 | Snyk

The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.

CVE
#dos#js
  • Attack Complexity

    Low

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

  • snyk-id

    SNYK-JS-PARSELINKHEADER-1582783

  • published

    19 Dec 2021

  • disclosed

    19 Dec 2021

  • credit

    DangKhai

How to fix?

Overview

PoC

Details

References

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907