Medium severity5.3NVD Advisory· Published Jan 18, 2023· Updated Jun 17, 2026
CVE-2022-25901
CVE-2022-25901
Description
Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cookiejarnpm | < 2.1.4 | 2.1.4 |
org.webjars.npm:cookiejarMaven | <= 2.1.3 | — |
Affected products
4- cpe:2.3:a:cookiejar_project:cookiejar:*:*:*:*:*:node.js:*:*Range: <=2.1.3
- cookiejar/cookiejardescription
- ghsa-coords2 versions
<= 2.1.3+ 1 more
- (no CPE)range: <= 2.1.3
- (no CPE)range: < 2.1.4
Patches
Vulnerability mechanics
References
9- github.com/bmeck/node-cookiejar/pull/39nvdPatchThird Party AdvisoryWEB
- github.com/bmeck/node-cookiejar/pull/39/commits/eaa00021caf6ae09449dde826108153b578348e5nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3176681nvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-COOKIEJAR-3149984nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h452-7996-h45hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25901ghsaADVISORY
- github.com/bmeck/node-cookiejar/blob/master/cookiejar.jsghsaWEB
- github.com/bmeck/node-cookiejar/blob/master/cookiejar.js%23L73nvdBroken LinkWEB
- lists.debian.org/debian-lts-announce/2023/09/msg00008.htmlnvdWEB
News mentions
0No linked articles in our index yet.