Vulnerabilities/

Improper Input Validation in is-email

Severity:
High

Description

is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.

Recommendation

Update the is-email package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
is-email
Anything's wrong? Let us know Last updated on February 01, 2023