Vulnerabilities/

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) (GHSA-545q-3fg6-48m7)

Severity:
Medium

Description

This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

Recommendation

Update the html-parse-stringify package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
html-parse-stringify
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing