Vulnerabilities/

is-url Inefficient Regular Expression Complexity vulnerability

Severity:
High

Description

A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is an unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue.

Recommendation

Update the is-url package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
is-url
Anything's wrong? Let us know Last updated on October 20, 2023