Vulnerabilities
Vulnerable Software
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
CVSS Score
6.5
EPSS Score
0.052
Published
2023-07-01
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
CVSS Score
7.5
EPSS Score
0.087
Published
2017-10-04


Contact Us

Shodan ® - All rights reserved