Vulnerabilities/

Regular Expression Denial of Service in underscore.string

Severity:
Medium

Description

Versions of underscore.string prior to 3.3.5 are vulnerable to Regular Expression Denial of Service (ReDoS).

The function unescapeHTML is vulnerable to ReDoS due to an overly-broad regex. The slowdown is approximately 2s for 50,000 characters but grows exponentially with larger inputs.

Recommendation

Update the underscore.string package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
underscore.string
Anything's wrong? Let us know Last updated on January 09, 2023