We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Es wurde eine problematische Schwachstelle in zhangyd-c OneBlog bis 2.3.9 ausgemacht. Es betrifft eine unbekannte Funktion der Komponente HTTP Header Handler. Durch Manipulation des Arguments X-Forwarded-For mit unbekannten Daten kann eine inefficient regular expression complexity-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Inefficient Regular Expression Complexity
2025-03-26: | Advisory disclosed |
2025-03-26: | VulDB entry created |
2025-03-26: | VulDB entry last update |
s1mple_xy (VulDB User)
vuldb.com/?id.301470 (VDB-301470 | zhangyd-c OneBlog HTTP Header redos)
vuldb.com/?ctiid.301470 (VDB-301470 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.521813 (Submit #521813 | https://github.com/zhangyd-c/OneBlog oneblog 2.3.9 redos)
github.com/zhangyd-c/OneBlog/issues/35
github.com/zhangyd-c/OneBlog/issues/35
Support options