Vulnerabilities/

Regular Expression Denial-of-Service in npm schema-inspector

Severity:
High

Description

What kind of vulnerability is it? Who is impacted? Email address validation is vulnerable to a denial-of-service attack where some input (for example a@0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.) will freeze the program or web browser page executing the code.

Recommendation

Update the schema-inspector package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
schema-inspector
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing