Vulnerabilities/

Regular Expression Denial of Service in timespan

Severity:
High

Description

Affected versions of timespan are vulnerable to a regular expression denial of service when parsing dates.

The amplification for this vulnerability is significant, with 50,000 characters resulting in the event loop being blocked for around 10 seconds.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
timespan
Anything's wrong? Let us know Last updated on September 13, 2023

This issue is available in SmartScanner Professional

See Pricing