GHSA-wrvr-8mpx-r7pp
GitHub Security Advisory
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Affected versions of `mime` are vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
## Recommendation
Update to version 2.0.3 or later.
Affected Packages
npm
mime
Affected versions:
2.0.0
(fixed in 2.0.3)
npm
mime
Affected versions:
0
(fixed in 1.4.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.