Description
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
Recommendation
Update the ansi-html package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.0.8
- Patched version(s): 0.0.8
References
Related Issues
- Uncontrolled Resource Consumption in trim-off-newlines - CVE-2021-23425
- Uncontrolled Resource Consumption in transpile - CVE-2021-23429
- Uncontrolled Resource Consumption in trim-newlines - CVE-2021-33623
- Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity - CVE-2025-58451
You might also like:
- Tags:
- npm
- ansi-html
Anything's wrong? Let us know Last updated on February 12, 2025


