CVE-2017-16098: Uncontrolled Resource Consumption
(updated )
charset is vulnerable to regular expression denial of service. Input of around k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE=
option the default header max length is kb, so the impact of the ReDoS is relatively low.
References
Detect and mitigate CVE-2017-16098 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →