CVE-2016-10527

HIGH

riot-compiler < 2.3.22 - Denial of Service via Catastrophic Backtracking

Title source: llm
STIX 2.1

Description

The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/86
Third Party Advisory x_refsource_misc
https://github.com/riot/compiler/issues/46

Scores

CVSS v3 7.5
EPSS 0.0160
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399 CWE-400
Status published
Products (2)
npm/riot-compiler 0 - 2.3.22npm
riot.js/riot-compiler 2.3.21
Published May 31, 2018
Tracked Since Feb 18, 2026