Description
A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely.
Recommendation
Update the urlregex package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.5.1
- Patched version(s): 0.5.1
References
Related Issues
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500
- regular expression denial of service (ReDoS) - date-and-time - CVE-2020-26289
- Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimend - CVE-2020-28500
You might also like:
- Tags:
- npm
- urlregex
Anything's wrong? Let us know Last updated on September 03, 2024


