Vulnerability Details CVE-2021-39157
detect-character-encoding is an open source character encoding inspection library. In detect-character-encoding v0.6.0 and earlier, data matching no charset causes the Node.js process to crash. The problem has been patched in [detect-character-encoding v0.7.0](https://github.com/sonicdoe/detect-character-encoding/releases/tag/v0.7.0). No workaround are available and all users should update to resolve this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-39157
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:-
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.1.0
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.2.0
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.2.1
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.3.0
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.3.1
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.4.0
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.5.0
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.5.1
-
cpe:2.3:a:detect-character-encoding_project:detect-character-encoding:0.6.0