CVE-2017-16117 describes a Regular Expression Denial of Service (ReDoS) vulnerability in the 'slug' module, which is used to slugify strings, including those with Unicode characters. Specially crafted, untrusted input can cause the event loop to block for approximately two seconds with only 50,000 characters, leading to a denial of service. This vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a network-based attack with low complexity and high availability impact, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.1CPE matchmatch criteria | cpe:2.3:a:slug_project:slug:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.