string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
- Severity:
- Low
Description
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.2.2
References
Related Issues
- jsPDF Bypass Regular Expression Denial of Service (ReDoS) - CVE-2025-29907
- tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability - CVE-2026-22809
- Valibot has a ReDoS vulnerability in `EMOJI_REGEX` - CVE-2025-66020
- Axios: Deep formToJSON Key Recursion Can Cause Denial of Service - Vulnerability
You might also like:
- Tags:
- npm
- string-math
Anything's wrong? Let us know Last updated on June 30, 2025


