Vulnerability Details CVE-2023-25166
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.4%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-25166
-
cpe:2.3:a:hapi:formula:1.0.0
-
cpe:2.3:a:hapi:formula:1.1.0
-
cpe:2.3:a:hapi:formula:1.2.0
-
cpe:2.3:a:hapi:formula:2.0.0
-
cpe:2.3:a:hapi:formula:3.0.0