CVE-2017-16026

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-16026
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16026.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-16026
Aliases
Published
2018-06-04T19:29:01Z
Modified
2025-02-19T02:20:39.142750Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Request is an http client. If a request is made using multipart, and the body type is a number, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.

References

Affected packages

Debian:11 / node-request

Package

Name
node-request
Purl
pkg:deb/debian/node-request?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.88.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / node-request

Package

Name
node-request
Purl
pkg:deb/debian/node-request?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.88.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/request/request

Affected ranges

Type
GIT
Repo
https://github.com/request/request
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.2.0

v2.*

v2.17.0
v2.18.0
v2.18.1
v2.19.0
v2.19.1
v2.20.0
v2.20.1
v2.21.0
v2.21.1
v2.22.0
v2.22.1
v2.23.0
v2.23.1
v2.24.0
v2.24.1
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.1
v2.28.0
v2.28.1
v2.29.0
v2.29.1
v2.30.0
v2.30.1
v2.31.0
v2.31.1
v2.32.0
v2.32.1
v2.33.0
v2.33.1
v2.34.0
v2.34.1
v2.35.0
v2.35.1
v2.36.0
v2.36.1
v2.37.0
v2.37.1
v2.38.0
v2.38.1
v2.39.0
v2.39.1
v2.40.0
v2.40.1
v2.41.0
v2.41.1
v2.42.0
v2.42.1
v2.43.0
v2.43.1
v2.44.0
v2.44.1
v2.45.0
v2.45.1
v2.46.0
v2.46.1