Description
is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Recommendation
Update the is-email package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.1
- Patched version(s): 1.0.1
References
Related Issues
- Improper Input Validation in sanitize-html - sanitize-html - CVE-2021-26540
- Improper Input Validation in sanitize-html - CVE-2021-26539
- Improper Input Validation in url-js - CVE-2022-25839
- Improper Input Validation in access-policy - CVE-2020-7674
You might also like:
- Tags:
- npm
- is-email
Anything's wrong? Let us know Last updated on February 01, 2023


