CVE-2017-16137 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting the debug_project debug module, where untrusted user input in the 'o' formatter can cause a denial of service. This is a low-severity issue with a CVSS score of 5.3, as it requires approximately 50,000 characters to block the system for only two seconds. There is no evidence of active exploitation, no known exploit code available (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.6.9CPE matchmatch criteria | cpe:2.3:a:debug_project:debug:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.1.0CPE matchmatch criteria | cpe:2.3:a:debug_project:debug:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.