Filtered by vendor Negotiator Project Subscriptions
Filtered by product Negotiator Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2016-10539 1 Negotiator Project 1 Negotiator 2024-09-17 N/A
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.