CVE-2023-25166EPSS p44.5%
CVE-2023-25166CVE-2023-25166
hapi / formula
Description
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
Scoring
| CVSS | 5.5 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| EPSS | 0.61% probability of exploitation · percentile 44.5% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |