Vulnerabilities/

Regular expression denial of service in semver-regex

Severity:
Low

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method

Recommendation

Update the semver-regex package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
semver-regex
Anything's wrong? Let us know Last updated on July 19, 2023