Denial of Service Vulnerability in semver Package for Node.js
CVE-2015-8855
7.5HIGH
What is CVE-2015-8855?
The semver package for Node.js, prior to version 4.3.2, is vulnerable to a denial of service attack where an attacker can exploit a long version string. This scenario, categorized as a regular expression denial of service (ReDoS), may lead to significant CPU consumption, impacting the performance and availability of applications that rely on the semver package.