Description
A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is an unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue.
Recommendation
Update the is-url package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.3
- Patched version(s): 1.2.3
References
Related Issues
- skeemas Inefficient Regular Expression Complexity vulnerability - CVE-2018-25074
- Vercel ms Inefficient Regular Expression Complexity vulnerability - CVE-2017-20162
- rgb2hex vulnerable to inefficient regular expression complexity - CVE-2018-25061
- Luxon Inefficient Regular Expression Complexity vulnerability - CVE-2023-22467
You might also like:
- Tags:
- npm
- is-url
Anything's wrong? Let us know Last updated on October 20, 2023


