GHSA-9vvw-cc9w-f27h · Severity: high · Ecosystem: npm — debug Inefficient Regular Expression Complexity vulnerability
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.
Conclusion & alert: CVE-2017-20165 is rated Moderate Risk (41.9/100): CVSS Low severity, with medium exploitation likelihood (EPSS 2.03%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.58% | 2.03% | +0.45% |
| 2 | 2026-03-09 | 2.14% | 1.58% | -0.56% |
| 3 | 2026-01-27 | — | 2.14% | — |
Full EPSS history (25 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 3.1 | LOW |
|
2.1 | 1.4 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 2.7 | 2.0 | LOW |
|
5.1 | 2.9 | [email protected] |
GHSA-9vvw-cc9w-f27h · Severity: high · Ecosystem: npm — debug Inefficient Regular Expression Complexity vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2017-20165 not yet assigned priority: Debian including 1 source packages (node-debug), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-20165 |
ubuntu
|
medium | CVE-2017-20165 medium priority: Ubuntu including 1 source packages (node-debug), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 9, needs-triage 2, ignored 1, released 1. | https://ubuntu.com/security/CVE-2017-20165 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| debug_project | debug | < 2.6.9 | cpe:2.3:a:debug_project:debug:*:*:*:*:*:node.js:*:* |
| debug_project | debug | >= 3.0.0, < 3.1.0 | cpe:2.3:a:debug_project:debug:*:*:*:*:*:node.js:*:* |
| URL | Tags |
|---|---|
| https://github.com/debug-js/debug/commit/c38a0166c266a679c8de012d4eaccec3f944e685 | Patch |
| https://github.com/debug-js/debug/pull/504 | Patch |
| https://github.com/debug-js/debug/releases/tag/3.1.0 | Release Notes |
| https://vuldb.com/?ctiid.217665 | Third Party Advisory VDB Entry |
| https://vuldb.com/?id.217665 | Third Party Advisory VDB Entry |