The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://github.com/broofa/node-mime/issues/167 | third party advisory exploit |
https://nodesecurity.io/advisories/535 | third party advisory |