CVE-2017-16138: Mime Project Mime

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

Affected products

  • Mime Project Mime: before 1.4.1 (fixed in 1.4.1); from 2.0.1, before 2.0.3 (fixed in 2.0.3)

Published 2018-06-07. Last modified 2026-10-07.