CVE-2024-41655
HIGHtf2-item-format 4.2.6-5.9.13 - Regular Expression Denial of Service via Crafted User Input
Title source: llmDescription
TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input. Version `5.9.14` contains a fix for the issue.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/danocmx/node-tf2-item-format/security/advisories/GHSA-8h55-q5qq-p685
Patch x_refsource_misc
https://github.com/danocmx/node-tf2-item-format/commit/5cffcc16a9261d6a937bda72bfe6830e02e31eec
Release Notes x_refsource_misc
https://github.com/danocmx/node-tf2-item-format/releases/tag/v5.9.14
Scores
CVSS v3
7.5
EPSS
0.0077
EPSS Percentile
50.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
CWE-624
Status
published
Products (2)
danocmx/node-tf2-item-format
>= 4.2.6, < 5.9.14
npm/tf2-item-format
4.2.6 - 5.9.14npm
Published
Jul 23, 2024
Tracked Since
Feb 18, 2026