negotiator is an HTTP content negotiator for Node.js and is...
Vulnerability Description
negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-10539
Credits & Attribution
No credits recorded in the NVD database.
References
More from HackerOne
View All →Affected Vendor
HackerOne
View all reports →