Description
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.0.0
References
Related Issues
- glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex - CVE-2020-28469
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
- useragent Regular Expression Denial of Service vulnerability - CVE-2020-26311
- is_js vulnerable to Regular Expression Denial of Service - CVE-2020-26302
You might also like:
- Tags:
- npm
- url-regex
Anything's wrong? Let us know Last updated on January 09, 2023


