Vulnerabilities/

Regular expression denial of service in devcert

Severity:
High

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

Recommendation

Update the devcert package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
devcert
Anything's wrong? Let us know Last updated on November 29, 2023

This issue is available in SmartScanner Professional

See Pricing