Vulnerabilities/

Regular Expression Denial of Service in Acorn

Severity:
High

Description

Affected versions of acorn are vulnerable to Regular Expression Denial of Service. A regex in the form of /[x-\ud800]/u causes the parser to enter an infinite loop. The string is not valid UTF16 which usually results in it being sanitized before reaching the parser.

Recommendation

Update the acorn package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
acorn
Anything's wrong? Let us know Last updated on January 09, 2023