Description
Versions of validator prior to 13.7.0 are affected by an inefficient Regular Expression complexity when using the rtrim and trim sanitizers.
Recommendation
Update the validator package to the latest compatible version. Followings are version details:
- Affected version(s): >= 11.1.0, < 13.7.0
- Patched version(s): 13.7.0
References
Could your website be exposed too?
SmartScanner can check your website for Inefficient Regular Expression Complexity in Validator.js - validator and gives you actionable findings to investigate.
Start a free scanRelated Issues
- string-kit Inefficient Regular Expression Complexity vulnerability - CVE-2021-4299
- skeemas Inefficient Regular Expression Complexity vulnerability - CVE-2018-25074
- is-url Inefficient Regular Expression Complexity vulnerability - CVE-2018-25079
- Vercel ms Inefficient Regular Expression Complexity vulnerability - CVE-2017-20162
You might also like:
See something that needs correcting? Let us knowUpdated January 11, 2023


