Vulnerabilities/

Regular Expression Denial of Service in slug

Severity:
Medium

Description

Affected versions of slug are vulnerable to a regular expression denial of service when parsing untrusted user input.

The issue is low severity, as it takes 50,000 characters to cause the event loop to block for 2 seconds,

About 50k characters can block the event loop for 2 seconds.

Recommendation

Update the slug package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
slug
Anything's wrong? Let us know Last updated on January 12, 2023

This issue is available in SmartScanner Professional

See Pricing