Withdrawn: cacheable-request depends on http-cache-semantics, which is vulnerable to Regular Expression Denial of Service
High severity
GitHub Reviewed
Published
Feb 11, 2023
to the GitHub Advisory Database
•
Updated Feb 21, 2023
Withdrawn
This advisory was withdrawn on Feb 14, 2023
Description
Published to the GitHub Advisory Database
Feb 11, 2023
Reviewed
Feb 11, 2023
Withdrawn
Feb 14, 2023
Last updated
Feb 21, 2023
This advisory is withdawn.
cacheable-request depends on http-cache-semanttics, which contains an Inefficient Regular Expression Complexity in versions prior to 4.1.1 of that package. cacheable-request has been updated to rely on the fixed version in 10.2.7.
Summary of http-cache-semantics vulnerability
http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Details
GHSA-rc47-6667-2j5j
References