CVE-2024-41655CWE-1333CWE-624

TF2 Item Format Regular Expression Denial of Service vulnerability

High · published July 23, 2024

CVSS v3.1
7.5
EPSS
1%
Percentile
53.1
In the wild
Unconfirmed
What it is

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input. Version `5.9.14` contains a fix for the issue.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00766 · 53.1th percentile
Weaknesses
CWE-1333 · Inefficient Regular Expression Complexity; CWE-624 · Executable Regular Expression Error
Published
2024-07-23T14:49Z
EPSS history
Timeline
  • 23 JUL 14:49Z
    TF2 Item Format Regular Expression Denial of Service vulnerability
    cvelistv5