{"id":"CVE-2017-16098","details":"charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.","aliases":["GHSA-9cp3-fh5x-xfcj"],"modified":"2026-07-08T12:06:36.604338Z","published":"2018-06-07T02:29:02.113Z","references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/524"},{"type":"EVIDENCE","url":"https://github.com/node-modules/charset/issues/10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/node-modules/charset","events":[{"introduced":"0"},{"fixed":"dcc48ee609a9b8a137c68faad712c646fcaeda29"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:charset_project:charset:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0.1"}]}}],"versions":["1.0.0","0.1.0","0.0.2","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16098.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}