CVE-2017-16136: Expressjs Method-Override
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
Affected products
- Expressjs Method-Override: before 2.3.10 (fixed in 2.3.10)
Published 2018-06-07. Last modified 2026-06-17.