Description
All versions of url-relative are vulnerable to Denial of Service. If the values to and from are equal, the function hangs and never returns. This may cause a Denial of Service.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Denial of Service in url-relative and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service in markdown - Vulnerability
- Denial of Service (DoS) vulnerability in RSSHub - CVE-2022-31110
- Denial of Service in rgb2hex - Vulnerability
- s3-url-parser vulnerable to Denial of Service via regexes component - CVE-2024-25355
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


