Regular Expression Parsing Vulnerability in NodeJS Tough-Cookie by Salesforce
CVE-2016-1000232
5.3MEDIUM
What is CVE-2016-1000232?
NodeJS Tough-Cookie version 2.2.2 is susceptible to a Regular Expression Parsing vulnerability in its HTTP request Cookie Header parsing. This flaw could lead to a Denial of Service attack if exploited through Custom HTTP headers sent by a client. To mitigate this risk, users are encouraged to upgrade to version 2.3.0, where the issue has been addressed.