Vulnerabilities/

Sanitize-html Vulnerable To REDoS Attacks

Severity:
High

Description

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

Recommendation

Update the sanitize-html package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sanitize-html
Anything's wrong? Let us know Last updated on April 22, 2024

This issue is available in SmartScanner Professional

See Pricing