Vulnerabilities/

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtrack

Severity:
Medium

Description

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces followed by a newline and “@”, an attacker can exploit inefficient regular expression processing, leading to excessive resource consumption.

Recommendation

Update the @octokit/request-error package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@octokit/request-error
Anything's wrong? Let us know Last updated on February 14, 2025

This issue is available in SmartScanner Professional

See Pricing