2.6
CVSSv2

CVE-2025-4727

CVSSv4: 6.3 | CVSSv3: 3.7 | CVSSv2: 2.6 | VMScore: 730 | EPSS: 0.00067 | KEV: Not Included
Published: 15/05/2025 Updated: 16/05/2025

Vulnerability Summary

Remote Regular Expression Complexity Vulnerability in Meteor Framework Up to 3.2.1

A vulnerability exists in Meteor up to version 3.2.1 within the Object.assign function in the packages/ddp-server/livedata_server.js file. The issue involves inefficient regular expression complexity when manipulating the forwardedFor argument. This vulnerability can potentially be initiated remotely, with a high attack complexity and difficult exploitation. The vulnerability has been publicly disclosed, and an exploit may be available. Users are strongly recommended to upgrade to Meteor version 3.2.2, which addresses the problem through a patch identified by the commit hash f7ea6817b90952baaea9baace2a3b4366fee6a63.

Vulnerable Product Search on Vulmon Subscribe to Product

* meteor