CVE-2017-16138

Executive Summary

The mime module versions <1.4.1, 2.0.1, 2.0.2 are vulnerable to a regular expression denial‑of‑service (ReDoS) when performing a mime lookup on untrusted input. An attacker can craft data that forces the regex engine to consume excessive CPU time, causing service disruption. This vulnerability is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2018-06-07T02:29:03.863 - Last Modified: 2026-10-07T21:17:01.333

Original Description: The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

"In separateness lies the world's great misery, in compassion lies the world's true strength."

— Buddha
Source: NVD