CVE-2015-8858

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."
Configurations

Configuration 1 (hide)

cpe:2.3:a:uglifyjs_project:uglifyjs:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2017-01-23 21:59

Updated : 2023-12-10 12:01


NVD link : CVE-2015-8858

Mitre link : CVE-2015-8858

CVE.ORG link : CVE-2015-8858


JSON object : View

Products Affected

uglifyjs_project

  • uglifyjs
CWE
CWE-399

Resource Management Errors