CVE-2017-1000189: Ejs

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()

Affected products

  • Ejs Ejs: before 2.5.5 (fixed in 2.5.5)

Published 2017-11-17. Last modified 2026-06-17.