CVE-2022-31110

MEDIUM

RSSHub <5c4177441417 - DoS

Title source: llm
STIX 2.1

Description

RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. This results in an impact on the performance of the servers and RSSHub services which may lead to a denial of service. This issue has been fixed in commit 5c4177441417 and all users are advised to upgrade. There are no known workarounds for this issue.

Scores

CVSS v3 5.3
EPSS 0.0056
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333 CWE-400
Status published
Products (2)
npm/rsshub 0npm
rsshub/rsshub < 2022-06-21
Published Jun 29, 2022
Tracked Since Feb 18, 2026