Vulnerabilities/

Regular Expression Denial of Service in uglify-js

Severity:
High

Description

Versions of uglify-js prior to 2.6.0 are affected by a regular expression denial of service vulnerability when malicious inputs are passed into the parse() method.

Recommendation

Update the uglify-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
uglify-js
Anything's wrong? Let us know Last updated on April 11, 2023

This issue is available in SmartScanner Professional

See Pricing