CVE-2017-15010: High severity Salesforce Tough-cookie Node.js vulnerability

Published Sep 21, 2017
·
Updated

A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.

Other sources

Affected versions of tough-cookie are susceptible to a regular expression denial of service.

The amplification on this vulnerability is relatively low - it takes around 2 seconds for the engine to execute on a malicious input which is 50,000 characters in length.

If node was compiled using the -DHTTPMAXHEADERSIZE however, the impact of the vulnerability can be significant, as the primary limitation for the vulnerability is the default max HTTP header length in node.

Recommendation

Update to version 2.3.3 or later.

It was found that the tough-cookie module is vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds.

Unless node was compiled using the -DHTTPMAXHEADERSIZE= option the default header max length is 80kb so the impact of the ReDoS is limited to around 7.3 seconds of blocking.

Upstream issue:

https://github.com/salesforce/tough-cookie/issues/92

Upstream patch: https://github.com/salesforce/tough-cookie/commit/98e0916d7b017669c93855d831c6e0b19c14141e

Red Hat

Node.js is vulnerable to a denial of service, caused by a flaw in the tough-cookie module. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause a regular expression denial of service.

IBM

Affected Software

5 affected componentsFixes available
npm/tough-cookie<2.3.3
2.3.3
redhat/tough-cookie<2.3.3
2.3.3
Salesforce Tough-cookie Node.js<=2.3.2
IBM Cognos Analytics<=12.0.0-12.0.4
IBM Cognos Analytics<=11.2.0-11.2.4 FP4

Event History

Oct 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Jul 24, 2018
Advisory Published
08:14 PM
Feb 4, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-15010?

CVE-2017-15010 is classified as a high severity vulnerability due to its potential to cause denial of service by overwhelming system resources.

2

How do I fix CVE-2017-15010?

To remediate CVE-2017-15010, upgrade the tough-cookie module to version 2.3.3 or later.

3

What causes the CVE-2017-15010 vulnerability?

CVE-2017-15010 is caused by a regular expression denial of service (ReDoS) flaw within the tough-cookie module.

4

Which versions of tough-cookie are affected by CVE-2017-15010?

Versions of tough-cookie prior to 2.3.3 are affected by CVE-2017-15010.

5

What applications are impacted by CVE-2017-15010?

Applications using the tough-cookie module before version 2.3.3 are at risk of being impacted by CVE-2017-15010.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203