Vulnerability Description
TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input. Version `5.9.14` contains a fix for the issue.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/danocmx/node-tf2-item-format/commit/5cffcc16a9261d6a937bda72b
- https://github.com/danocmx/node-tf2-item-format/releases/tag/v5.9.14
- https://github.com/danocmx/node-tf2-item-format/security/advisories/GHSA-8h55-q5
- https://github.com/danocmx/node-tf2-item-format/commit/5cffcc16a9261d6a937bda72b
- https://github.com/danocmx/node-tf2-item-format/releases/tag/v5.9.14
- https://github.com/danocmx/node-tf2-item-format/security/advisories/GHSA-8h55-q5
FAQ
What is CVE-2024-41655?
CVE-2024-41655 is a vulnerability with a CVSS score of 7.5 (HIGH). TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Se...
How severe is CVE-2024-41655?
CVE-2024-41655 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41655?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.