Vulnerabilities/

Regular Expression Denial of Service in papaparse

Severity:
High

Description

Versions of papaparse prior to 5.2.0 are vulnerable to Regular Expression Denial of Service (ReDos). The parse function contains a malformed regular expression that takes exponentially longer to process non-numerical inputs. This allows attackers to stall systems and lead to Denial of Service.

Recommendation

Update the papaparse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
papaparse
Anything's wrong? Let us know Last updated on June 16, 2025

This issue is available in SmartScanner Professional

See Pricing