CVE Database
/

CVE-2017-16136

Back to search

CVE-2017-16136

Published: Jun 7, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

VendorProductVersions

HackerOne

method-override node module

affected
<= 1.0.2 || > 2.0.0 < 2.3.10

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now