Description
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.2.2
References
Could your website be exposed too?
SmartScanner can check your website for string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF Bypass Regular Expression Denial of Service (ReDoS) - CVE-2025-29907
- tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability - CVE-2026-22809
- Valibot has a ReDoS vulnerability in `EMOJI_REGEX` - CVE-2025-66020
- Axios: Deep formToJSON Key Recursion Can Cause Denial of Service - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated June 30, 2025


