Description
Versions of tf2-item-format since at least 4.2.6 are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input.
Recommendation
Update the tf2-item-format package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.2.6, <= 5.9.13
- Patched version(s): 5.9.14
References
Related Issues
- Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing - CVE-2024-1899
- parse-uri Regular expression Denial of Service (ReDoS) - CVE-2024-36751
- parse-uri Regular expression Denial of Service (ReDoS) - parse-uri - CVE-2024-36751
- Marked allows Regular Expression Denial of Service (ReDoS) attacks - CVE-2018-25110
You might also like:
- Tags:
- npm
- tf2-item-format
Anything's wrong? Let us know Last updated on August 02, 2024


