Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29060

20
FAUCET Score

CVE-2021-29060 is a Regular Expression Denial of Service (ReDOS) vulnerability affecting Color-String versions 1.5.5 and below. It occurs when the application processes a specially crafted, invalid HWB string, leading to a denial of service. The vulnerability has a CVSS score of 5.3 (Medium), indicating it can be exploited remotely with low attack complexity, resulting in low availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.5.5CPE matchmatch criteria
cpe:2.3:a:color-string_project:color-string:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.13%
Probability of exploitation in next 30 days
EPSS Percentile
86.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0313 is in the 81st percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: color-stringFixed in: 1.5.5
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-prometheus-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-thanos-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-prometheus
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 1Fixed in: servicemesh-prometheus
redhatend of lifevia redhat_api
Product: Red Hat Virtualization 4Fixed in: ovirt-web-ui
redhatend of lifevia redhat_api
Product: Red Hat Virtualization 4Fixed in: ovirt-engine-ui-extensions
redhatend of lifevia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 1Fixed in: servicemesh-grafana

Vendor Advisories (3)

bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
npmGHSA-257v-vj4p-3w2hmedium

Regular Expression Denial of Service (ReDOS)

Jun 22, 2021
redhatCVE-2021-29060Moderate

nodejs-color-string: Regular expression denial of service when the application is provided and checks a crafted invalid HWB string

Jun 21, 2021

References

github.com / Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375ac9d3
PatchThird Party Advisory
github.com / yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.md
ExploitPatchThird Party Advisory
github.com / yetingli/SaveResults/blob/main/js/color-string.js
Third Party Advisory
npmjs.com / package/color-string
Product