CVE-2023-26103
MEDIUMdeno < 1.31.0 - Regular Expression Denial of Service via WebSocket Header Parsing
Title source: llmDescription
Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.
References (5)
Core 5
Core References
Release Notes
https://github.com/denoland/deno/releases/tag/v1.31.0
Exploit, Technical Description, Third Party Advisory
https://security.snyk.io/vuln/SNYK-RUST-DENO-3315970
Scores
CVSS v3
5.3
EPSS
0.0123
EPSS Percentile
64.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (2)
crates.io/deno
1.12.0 - 1.31.0crates.io
deno/deno
< 1.31.0
Published
Feb 25, 2023
Tracked Since
Feb 18, 2026