Vulnerabilities/

Regular Expression Denial of Service (GHSA-qx4v-6gc5-f2vv)

Severity:
Medium

Description

A Regular Expression Denial of Service vulnerability was discovered in esm before 3.1.0. The issue is that esm’s find-indexes is using the unescaped identifiers in a regex, which, in this case, causes an infinite loop.

Recommendation

Update the esm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
esm
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing