CVE-2019-0820
Regular Expression Denial of Service in System.Text.RegularExpressions
7.5
HIGH
CVSS 3.1
EPSS 5.7%
Description
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
How to fix CVE-2019-0820
To remediate CVE-2019-0820, upgrade the affected package to a fixed version below.
- —upgrade to 4.3.1 or later
Is CVE-2019-0820 being exploited?
Moderate — EPSS is 5.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 4.3.0, < 4.3.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |