{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T13:12:42.294","vulnerabilities":[{"cve":{"id":"CVE-2017-16136","sourceIdentifier":"support@hackerone.com","published":"2018-06-07T02:29:03.770","lastModified":"2026-06-17T01:08:51.410","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header."},{"lang":"es","value":"method-override es un módulo empleado por el framework Express.js para permitir el uso de verbos HTTP como PUT o DELETE en lugares no soportados por el cliente. method-override es vulnerable a una denegación de servicio (DoS) por expresiones regulares cuando se pasan entradas especialmente manipuladas para que sean analizadas por la cabecera X-HTTP-Method-Override."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"HackerOne","product":"method-override node module","versions":[{"version":"<= 1.0.2 || > 2.0.0 < 2.3.10","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:expressjs:method-override:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2.3.10","matchCriteriaId":"151AB27E-8444-4579-A27A-A3AEB2C78A27"}]}]}],"references":[{"url":"https://nodesecurity.io/advisories/538","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://nodesecurity.io/advisories/538","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}