{"id":"CVE-2021-23490","aliases":["GHSA-q674-xm3x-2926"],"url":"https://o3.security/vulnerability/CVE-2021-23490","summary":"Uncontrolled Resource Consumption in parse-link-header","details":"The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.","published":"2021-12-24T20:15:08.013Z","modified":"2026-07-08T23:58:49.990514Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01831,"percentile":0.76907,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"parse-link-header","fixedVersion":"2.0.0"}],"fix":{"url":"https://github.com/thlorenz/parse-link-header/commit/72f05c717b3f129c5331a07bf300ed8886eb8ae1","label":"thlorenz/parse-link-header@72f05c7"},"references":[{"type":"FIX","url":"https://github.com/thlorenz/parse-link-header/commit/72f05c717b3f129c5331a07bf300ed8886eb8ae1"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2321973"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-PARSELINKHEADER-1582783"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:58:49.990514Z"}}