Description
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
Remediation
References
https://nodesecurity.io/advisories/538
Related Vulnerabilities
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:tomcat-jasper
CVE-2021-23377 Vulnerability in npm package onion-oled-js
CVE-2020-13946 Vulnerability in maven package org.apache.cassandra:cassandra-all
CVE-2022-36007 Vulnerability in maven package com.github.jlangch:venice
CVE-2022-24881 Vulnerability in maven package com.hccake:ballcat-codegen