CVE-2023-26103: High severity deno vulnerability
Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s,s/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-26103?
CVE-2023-26103 is a vulnerability in the package deno before version 1.31.0 that allows for Regular Expression Denial of Service (ReDoS) attacks.
What is Regular Expression Denial of Service (ReDoS)?
Regular Expression Denial of Service (ReDoS) is a type of security vulnerability that can crash or freeze an application by exploiting inefficient regular expressions.
How does CVE-2023-26103 exploit the vulnerability?
CVE-2023-26103 exploits the vulnerability by using a specially crafted Connection/Upgrade header that triggers regular expression processing, leading to a Denial of Service (DoS) attack.
What is the severity of CVE-2023-26103?
The severity of CVE-2023-26103 is rated as high with a severity value of 7.5.
How can I fix the CVE-2023-26103 vulnerability?
To fix the CVE-2023-26103 vulnerability, upgrade the deno package to version 1.31.0 or higher.