CVE-2017-16115
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Affected products
HackerOne · timespan node module