5
CVSSv2

CVE-2021-33502

Published: 24/05/2021 Updated: 08/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The normalize-url package prior to 4.5.1, 5.x prior to 5.3.1, and 6.x prior to 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

normalize-url project normalize-url

normalize-url project normalize-url 6.0.0

Vendor Advisories

Debian Bug report logs - #989258 CVE-2021-33502 Package: node-got; Maintainer for node-got is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-got is src:node-got (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 30 May 2021 16:06:01 UTC Se ...
Synopsis Moderate: RHV Manager (ovirt-engine) [ovirt-450] security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated ovirt-engine packages that fix several bugs and add various enhancements are now available ...
Synopsis Moderate: nodejs and nodejs-nodemon security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nodejs and nodejs-nodemon is now available for Red Hat Enterprise Linux 9Red Hat Produ ...
Synopsis Moderate: nodejs:14 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8Red Hat Product Secu ...
The normalize-url package before 451, 5x before 531, and 6x before 601 for Nodejs has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs ...