Description
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 4.0.0, <= 4.5.1
References
Could your website be exposed too?
SmartScanner can check your website for Regular Expression Denial of Service (ReDoS) in lodash - lodash.trim and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimend - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash - CVE-2019-1010266
You might also like:
See something that needs correcting? Let us knowUpdated September 29, 2025


