CVE-2022-25940: Lite-Server Project Lite-Server
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Affected products
- Lite-Server Project Lite-Server: affected versions not specified
Published 2022-12-20. Last modified 2026-06-17.