Description
is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Recommendation
Update the is-email package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.1
- Patched version(s): 1.0.1
References
Could your website be exposed too?
SmartScanner can check your website for Improper Input Validation in is-email and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Input Validation in sanitize-html - sanitize-html - CVE-2021-26540
- Improper Input Validation in sanitize-html - CVE-2021-26539
- Improper Input Validation in url-js - CVE-2022-25839
- Improper Input Validation in access-policy - CVE-2020-7674


