VYPR

npm package

websocket-extensions

pkg:npm/websocket-extensions

Vulnerabilities (1)

  • CVE-2020-7662Jun 2, 2020
    affected < 0.1.4fixed 0.1.4

    websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and