{"success":true,"data":{"threats":[{"id":"8dd6b957-02a4-492e-b03d-bbdbda2b87e6","slug":"cve-2017-16119","externalId":"CVE-2017-16119","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2017-16119 — Fresh is a module used by the Express.js framework for HTTP response freshness testing.","description":"Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.","cveId":"CVE-2017-16119","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"fresh project","product":"fresh","affectedVersions":["< 0.5.2"],"cwes":["CWE-400"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://nodesecurity.io/advisories/526","type":"advisory","title":"Third Party Advisory"},{"url":"https://nodesecurity.io/advisories/526","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.01584,"epssPercentile":0.74819,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2018-06-07T02:29:02.987Z","addedAt":"2026-10-08T21:05:41.154Z","updatedAt":"2026-10-08T21:05:41.154Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16119","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2017-16119","note":"authoritative record"}],"raw":{"id":"CVE-2017-16119","cveTags":[],"metrics":{"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2017-16119","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"version":"2.0.3","timestamp":"2026-10-08T19:41:42.770932Z"}}],"cvssMetricV2":[{"type":"Primary","source":"nvd@nist.gov","cvssData":{"version":"2.0","baseScore":5,"accessVector":"NETWORK","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","authentication":"NONE","integrityImpact":"NONE","accessComplexity":"LOW","availabilityImpact":"PARTIAL","confidentialityImpact":"NONE"},"acInsufInfo":true,"impactScore":2.9,"baseSeverity":"MEDIUM","obtainAllPrivilege":false,"exploitabilityScore":10,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"cvssMetricV30":[{"type":"Primary","source":"nvd@nist.gov","cvssData":{"scope":"UNCHANGED","version":"3.0","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"},"impactScore":3.6,"exploitabilityScore":3.9}],"cvssMetricV31":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","cvssData":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"},"impactScore":3.6,"exploitabilityScore":3.9}]},"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"HackerOne","product":"fresh node module","versions":[{"status":"affected","version":"< 0.5.2"}]}]}],"published":"2018-06-07T02:29:02.987","references":[{"url":"https://nodesecurity.io/advisories/526","tags":["Third Party Advisory"],"source":"support@hackerone.com"},{"url":"https://nodesecurity.io/advisories/526","tags":["Third Party Advisory"],"source":"af854a3a-2127-422b-91ae-364da2661108"}],"vulnStatus":"Modified","weaknesses":[{"type":"Secondary","source":"support@hackerone.com","description":[{"lang":"en","value":"CWE-400"}]},{"type":"Primary","source":"nvd@nist.gov","description":[{"lang":"en","value":"CWE-400"}]}],"descriptions":[{"lang":"en","value":"Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition."},{"lang":"es","value":"Fresh es un módulo empleado por el framework Express.js para las pruebas de \"frescura\" de las respuestas HTTP. Es vulnerable a una denegación de servicio (DoS) por expresiones regulares cuando se le pasan entradas especialmente manipuladas para su análisis. Esto provoca que el bucle de eventos se bloquee, provocando una condición de denegación de servicio (DoS)."}],"lastModified":"2026-10-08T20:17:26.467","configurations":[{"nodes":[{"negate":false,"cpeMatch":[{"criteria":"cpe:2.3:a:fresh_project:fresh:*:*:*:*:*:node.js:*:*","vulnerable":true,"matchCriteriaId":"9BB3B576-C56A-4C4F-A0EF-F295392C4285","versionEndExcluding":"0.5.2"}],"operator":"OR"}]}],"sourceIdentifier":"support@hackerone.com"}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:11:06.344Z","durationMs":5,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2017-16119","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}