Inefficient Regular Expression Complexity in Validator.js (GHSA-xx4c-jj58-r7x6)
- Severity:
- Medium
Description
Versions of validator prior to 13.7.0 are affected by an inefficient Regular Expression complexity when using the rtrim and trim sanitizers.
Recommendation
Update the validator package to the latest compatible version. Followings are version details:
- Affected version(s): >= 11.1.0, < 13.7.0
- Patched version(s): 13.7.0
References
Related Issues
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200
- Regular Expression Denial of Service (ReDoS) in lodash (GHSA-29mw-wpgm-hmr9) 2 - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash (GHSA-x5rq-j2xg-h7qm) - CVE-2019-1010266
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Tags:
- npm
- validator
Anything's wrong? Let us know Last updated on January 11, 2023