Vulnerabilities/

uri-template-lite Regular Expression Denial of Service

Severity:
Medium

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the “URI.expand” method.

Recommendation

Update the uri-template-lite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
uri-template-lite
Anything's wrong? Let us know Last updated on November 28, 2023