CVE-2022-25940

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.12 % (47th)
0.12% Progress
Affected Products 1
Advisories 2

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Snyk
Published Date
2022-12-20 05:15:11
(21 months ago)
Updated Date
2022-12-29 18:36:30
(20 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Lite-server Project Lite-server for Node.js cpe:2.3:a:lite-server_project:lite-server:-:*:*:*:*:node.js
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...