Vulnerabilities/

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Severity:
Medium

Description

This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
html-parse-stringify2
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing