{"id":"CVE-2016-10703","details":"A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.","aliases":["GHSA-pm9p-9926-w68m"],"modified":"2026-08-18T08:15:12.954921Z","published":"2017-12-14T19:29:00.197Z","references":[{"type":"ADVISORY","url":"https://advisory.checkmarx.net/advisory/CX-2016-4450"},{"type":"FIX","url":"https://github.com/jfhbrook/node-ecstatic/commit/71ce93988ead4b561a8592168c72143907189f01"},{"type":"FIX","url":"https://www.checkmarx.com/advisories/denial-of-service-dos-vulnerability-in-ecstatic-npm-package/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jfhbrook/node-ecstatic","events":[{"introduced":"0"},{"fixed":"c1a13e811a751efb45a4463fb32f6faf1720b49e"},{"fixed":"71ce93988ead4b561a8592168c72143907189f01"}],"database_specific":{"cpe":"cpe:2.3:a:ecstatic_project:ecstatic:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.4.1","1.4.0","1.3.1","1.3.0","1.2.0","1.1.3","1.1.2","1.1.1","1.1.0","1.0.1","1.0.0","0.8.0","0.7.6","0.7.5","0.7.3","0.7.2","0.7.1","0.7.0","0.6.1","0.6.0","v0.4.12","v0.4.11","v0.4.10","v0.4.2","v0.4.1","v0.1.6","v0.0.4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10703.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}