Description
RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.8
References
Related Issues
- glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - CVE-2020-28469
- Handling untrusted input can result in a crash, leading to loss of availability / denial of service - CVE-2024-30253
- youtube-regex vulnerable to Regex Denial of Service - CVE-2025-65122
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
You might also like:
- Tags:
- npm
- domain-suffix
Anything's wrong? Let us know Last updated on September 03, 2025


