logo

Database

Asymmetric denial of service In negotiator

Description

Regular Expression Denial of Service in negotiator Affected versions of negotiator are vulnerable to regular expression denial of service attacks, which trigger upon parsing a specially crafted Accept-Language header value.

Recommendation

Update to version 0.6.1 or later.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-1U54S – Vulnerability | Fluid Attacks Database