CVE-2015-8315: Vercel Ms

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

Affected products

  • Vercel Ms: before 0.7.1 (fixed in 0.7.1)

Published 2017-01-23. Last modified 2026-06-17.