Description
npm ssri 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Recommendation
Update the ssri package to the latest compatible version. Followings are version details:
Affected version(s): **= 8.0.0 >= 7.0.0, < 7.1.1 >= 5.2.2, < 6.0.2** Patched version(s): **8.0.1 7.1.1 6.0.2**
References
Could your website be exposed too?
SmartScanner can check your website for Regular Expression Denial of Service (ReDoS) - ssri and gives you actionable findings to investigate.
Start a free scanRelated Issues
- semver-regex Regular Expression Denial of Service (ReDOS) - CVE-2021-3795
- jspdf vulnerable to Regular Expression Denial of Service (ReDoS) - CVE-2021-23353
- Regular Expression Denial of Service (REDoS) in Marked - CVE-2021-21306
- Regular Expression Denial of Service (ReDoS) - CVE-2021-28092


