CVE-2022-25881
http-cache-semantics < 4.1.1 - Regular Expression Denial of Service (ReDoS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Esto afecta a las versiones del paquete http-cache-semantics anteriores a la 4.1.1. El problema se puede explotar mediante valores de encabezado de solicitud maliciosos enviados a un servidor, cuando ese servidor lee la política de caché de la solicitud utilizando esta librería.
A flaw was found in http-cache-semantics. When the server reads the cache policy from the request using this library, a Regular Expression Denial of Service occurs, caused by malicious request header values sent to the server.
The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 via the cache-control HTTP header. WordPress plugins and themes may be using this package, however, they may not be vulnerable to exploitation.
Multicluster Engine for Kubernetes 2.0.8 images Multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy. Issues addressed include a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2022-02-24 CVE Reserved
- 2023-01-31 CVE Published
- 2025-03-27 CVE Updated
- 2025-03-27 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1333: Inefficient Regular Expression Complexity
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/kornelski/http-cache-semantics/blob/master/index.js%23L83 | Broken Link | |
https://security.netapp.com/advisory/ntap-20230622-0008 |
|
URL | Date | SRC |
---|---|---|
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3253332 | 2025-03-27 | |
https://security.snyk.io/vuln/SNYK-JS-HTTPCACHESEMANTICS-3248783 | 2025-03-27 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-25881 | 2023-10-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2165824 | 2023-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Http-cache-semantics Project Search vendor "Http-cache-semantics Project" | Http-cache-semantics Search vendor "Http-cache-semantics Project" for product "Http-cache-semantics" | < 4.1.1 Search vendor "Http-cache-semantics Project" for product "Http-cache-semantics" and version " < 4.1.1" | node.js |
Affected
|