CVE Vulnerabilities

CVE-2022-25901

Inefficient Regular Expression Complexity

Published: Jan 18, 2023 | Modified: Feb 13, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
CookiejarCookiejar_project*2.1.3 (including)
Node-cookiejarUbuntulunar*
Node-cookiejarUbuntutrusty*
Node-cookiejarUbuntuupstream*
Node-cookiejarUbuntuxenial*

Potential Mitigations

References