{"id":"CVE-2023-26103","aliases":["GHSA-jc97-h3h9-7xh6"],"url":"https://o3.security/vulnerability/CVE-2023-26103","summary":"Regular Expression Denial of Service in Deno.upgradeWebSocket API","details":"### Impact\nVersions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server. \n\n### Patches\nIt is recommended that users upgrade to Deno 1.31.0.\n\n","published":"2023-02-25T05:00:01.387Z","modified":"2026-08-12T03:51:15.523227383Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"crates.io","name":"deno","fixedVersion":"1.31.0"}],"fix":{"url":"https://github.com/denoland/deno/commit/cf06a7c7e672880e1b38598fe445e2c50b4a9d06","label":"denoland/deno@cf06a7c"},"references":[{"type":"WEB","url":"https://github.com/denoland/deno/blob/2b247be517d789a37e532849e2e40b724af0918f/ext/http/01_http.js%23L395-L409"},{"type":"WEB","url":"https://github.com/denoland/deno/releases/tag/v1.31.0"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-RUST-DENO-3315970"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26103.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26103"},{"type":"FIX","url":"https://github.com/denoland/deno/commit/cf06a7c7e672880e1b38598fe445e2c50b4a9d06"},{"type":"FIX","url":"https://github.com/denoland/deno/pull/17722"},{"type":"WEB","url":"https://github.com/denoland/deno/security/advisories/GHSA-jc97-h3h9-7xh6"},{"type":"PACKAGE","url":"https://github.com/denoland/deno"},{"type":"WEB","url":"https://github.com/denoland/deno/blob/2b247be517d789a37e532849e2e40b724af0918f/ext/http/01_http.js#L395-L409"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.523227383Z"}}