CVE-2015-8855
HIGHNodejs Node.js < 4.3.1 - Resource Management Error
Title source: ruleDescription
The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
Scores
CVSS v3
7.5
EPSS
0.0109
EPSS Percentile
77.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-399
Status
draft
Affected Products (2)
nodejs/node.js
< 4.3.1
npm/semver
< 4.3.2npm
Timeline
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026