Description
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
Recommendation
Update the normalize-url package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.3.0, < 4.5.1 >= 6.0.0, < 6.0.1 >= 5.0.0, < 5.3.1** Patched version(s): **4.5.1 6.0.1 5.3.1**
References
Related Issues
- jspdf vulnerable to Regular Expression Denial of Service (ReDoS) - CVE-2021-23353
- ReDOS in IS-SVG - CVE-2021-29059
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
- html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - html-parse-stringify - CVE-2021-23346
You might also like:
- Tags:
- npm
- normalize-url
Anything's wrong? Let us know Last updated on November 29, 2023


