Vulnerabilities/

Regular Expression Denial of Service (ReDoS) (GHSA-vx3p-948g-6vhq)

Severity:
High

Description

npm ssri 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Recommendation

Update the ssri package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ssri
Anything's wrong? Let us know Last updated on September 21, 2023

This issue is available in SmartScanner Professional

See Pricing