HIGH🇵🇱 Wersja polska

CVE-2018-7158

CVSS 7.5v3.1pub. 2018-05-17upd. 2024-11-21

The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x. The regular expression, `splitPathRe`, used within the `'path'` module for the various path parsing functions, including `path.dirname()`, `path.extname()` and `path.parse()` was structured in such a way as to allow an attacker to craft a string, that when passed through one of these functions, could take a significant amount of time to evaluate, potentially leading to a full denial of service.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Node.js

    APP
    Nodejs
    4.0.0 – 4.1.24.2.0 – 4.9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-48930CRITICAL9.8PL ✓same product

Node.js TLS: błąd obsługi hostname z null-bajtem prowadzi do przekierowania authority

CVE-2025-55130CRITICAL9.1PL ✓same product

Obejście modelu uprawnień w Node.js poprzez spreparowane symlinki

CVE-2026-21636CRITICAL10.0PL ✓same product

Node.js: obejście modelu uprawnień przez Unix Domain Socket

CVE-2024-3566CRITICAL9.8PL ✓same product

Command injection w aplikacjach Windows korzystających z CreateProcess

CVE-2024-21896CRITICAL9.8PL ✓same product

Path traversal w Permission Model Node.js przez monkey-patching Buffer