Description
glob-parent 6.0.0 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1.
This vulnerability is separate from GHSA-ww39-953v-wcq6.
Recommendation
Update the glob-parent package to the latest compatible version. Followings are version details:
- Affected version(s): = 6.0.0
- Patched version(s): 6.0.1
References
- GHSA-cj88-88mr-972w
- www.mend.io
- security.snyk.io
- security.netapp.com
- CVE-2021-35065
- CWE-1333
- CWE-400
- CAPEC-310
- OWASP 2021-A6
Related Issues
- glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - CVE-2020-28469
- html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - CVE-2021-23346
- html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - html-parse-stringify - CVE-2021-23346
- jspdf vulnerable to Regular Expression Denial of Service (ReDoS) - CVE-2021-23353
You might also like:
- Tags:
- npm
- glob-parent
Anything's wrong? Let us know Last updated on April 14, 2025


