CVE-2023-25166: Regular Expression Denial of Service (ReDoS) Vulnerability
Published Feb 8, 2023
·Updated
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
Affected Software
1 affected component
Hapi Formula Node.js<3.0.1
Remediation
Event History
Feb 8, 2023
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25166?
CVE-2023-25166 has a severity that can lead to denial of service due to polynomial execution time vulnerabilities.
2
How do I fix CVE-2023-25166?
To fix CVE-2023-25166, upgrade to version 3.0.1 or later of the formula library.
3
What versions are affected by CVE-2023-25166?
CVE-2023-25166 affects versions of the formula library prior to 3.0.1.
4
Can I use a workaround for CVE-2023-25166?
There are no known workarounds for CVE-2023-25166; upgrading is required to mitigate the issue.
5
What does CVE-2023-25166 impact?
CVE-2023-25166 impacts the hapi formula library used in Node.js applications.