Candidate: CVE-2016-10539 PublicDate: 2018-05-31 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10539 https://nodesecurity.io/advisories/106 Description: negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-negotiator: upstream_node-negotiator: needs-triage precise/esm_node-negotiator: DNE trusty_node-negotiator: ignored (reached end-of-life) trusty/esm_node-negotiator: DNE (trusty was needed) xenial_node-negotiator: ignored (end of standard support, was needed) artful_node-negotiator: ignored (reached end-of-life) bionic_node-negotiator: released (0.6.1-1) cosmic_node-negotiator: released (0.6.1-1) disco_node-negotiator: released (0.6.1-1) eoan_node-negotiator: released (0.6.1-1) focal_node-negotiator: released (0.6.1-1) groovy_node-negotiator: released (0.6.1-1) hirsute_node-negotiator: released (0.6.1-1) impish_node-negotiator: released (0.6.1-1) jammy_node-negotiator: released (0.6.1-1) devel_node-negotiator: released (0.6.1-1)