Junglewise Threat Intelligence

CVE-2017-16136: method-override ReDoS in X-HTTP-Method-Override header

CVE-2017-16136 · Severity: low · CVSS 3 · Published 2018-07-24

Executive brief

method-override is a Node.js middleware library that allows HTTP clients to override the request method via a custom header. A regular expression denial-of-service (ReDoS) vulnerability allows an attacker to send specially crafted HTTP requests that cause the server to hang or become unresponsive, disrupting service availability for legitimate users.

Technical details

method-override contains a regular expression denial-of-service (ReDoS) vulnerability in its parsing of the X-HTTP-Method-Override header. The vulnerable component uses an inefficient regular expression that exhibits catastrophic backtracking when processing untrusted input with certain patterns. An attacker can send a crafted HTTP request with a malicious X-HTTP-Method-Override header value to cause excessive CPU consumption, leading to denial of service. No authentication or user interaction is required; the vulnerability is triggered by network-accessible HTTP headers. The fix, released in version 2.3.10, optimizes the header parsing logic to skip unnecessary regex evaluation.

Affected products

  • Express.js method-override 1.0.2 through 2.3.9

Timeline

  • 2018-07-24: disclosed
  • 2017: patched: Fix committed (version 2.3.10)

References