Description
Specially crafted titles may have caused a regular expression to excessively backtrack and cause a local denial of service.
Additional Details are available at Bugzilla
Credit: DayShift
Recommendation
Update the @mozilla/readability package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.0
- Patched version(s): 0.6.0
References
Related Issues
- youtube-regex vulnerable to Regex Denial of Service - CVE-2025-65122
- parse-duration has a Regex Denial of Service that results in event loop delay and out of memory - CVE-2025-25283
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
- domain-suffix RegEx Denial of Service - CVE-2024-25354
You might also like:
- Tags:
- npm
- @mozilla/readability
Anything's wrong? Let us know Last updated on March 26, 2025


