CVE-2017-16117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
07/06/2018
Last modified:
09/10/2019

Description

slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:slug_project:slug:*:*:*:*:*:node.js:*:* 0.9.1 (including)