7.8
CVSSv2

CVE-2015-8858

Published: 23/01/2017 Updated: 02/03/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The uglify-js package prior to 2.6.0 for Node.js allows malicious users to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."

Vulnerable Product Search on Vulmon Subscribe to Product

uglifyjs project uglifyjs

Github Repositories

[DEPRECATED] Javascript, css and image files hashing for nodejs/express

[DEPRECATED] Please I have no longer time for maintaining this package Previous version depended on old version of uglify-js which had security issues cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2015-8857 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2015-8858 PLEASE DO NOT USE THIS PACKAGE jcash This project is mostly for adapting solutions out there for my person