Vulnerability library
Security checkJanuary 27, 2023

Regular expression denial of service in react-native

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmreact-native

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

Recommendation

Update the react-native package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 0.63.0, < 0.64.1 >= 0.59.0, < 0.62.3**
  • Patched version(s): **0.64.1 0.62.3**

References

Could your website be exposed too?

SmartScanner can check your website for Regular expression denial of service in react-native and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 27, 2023