Description
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Regular expression denial of service in url-regex and gives you actionable findings to investigate.
Start a free scanRelated Issues
- glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - CVE-2020-28469
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
- useragent Regular Expression Denial of Service vulnerability - CVE-2020-26311
- is_js vulnerable to Regular Expression Denial of Service - CVE-2020-26302
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


