---
id: CVE-2017-16138
title: >-
  The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression
  denial of service when a mime lookup is performed on untrusted user input.
summary: >-
  The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression
  denial of service when a mime lookup is performed on untrusted user input.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: mime_project
product: mime
affected:
  - mime < 1.4.1
  - 'mime >= 2.0.1, < 2.0.3'
patched:
  - mime 2.0.3
published: '2018-06-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:01.333'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-16138'
references:
  - url: 'https://github.com/broofa/node-mime/issues/167'
    label: support@hackerone.com
  - url: 'https://nodesecurity.io/advisories/535'
    label: support@hackerone.com
  - url: 'https://github.com/broofa/node-mime/issues/167'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodesecurity.io/advisories/535'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.02153
epssPercentile: 0.81584
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T20:12:50.852688Z'
ingestedAt: '2026-10-07T20:46:46.993Z'
---

## Overview

The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

## Affected

- `mime < 1.4.1`
- `mime >= 2.0.1, < 2.0.3`

## Remediation

Upgrade past the affected range:

- `mime 2.0.3`
