NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-05T17:00:00

Updated: 2024-08-06T03:55:27.288Z

Reserved: 2016-10-28T00:00:00

Link: CVE-2016-1000232

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-09-05T17:29:00.373

Modified: 2018-10-31T15:02:32.663

Link: CVE-2016-1000232

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-07-22T00:00:00Z

Links: CVE-2016-1000232 - Bugzilla