Skip to main content

Vendor archive

cookiejar_project CVEs

Beta · best-effort

1 CVEs tagged to vendor cookiejar_project0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-25901

Published Jan 18, 2023

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular express…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1