Description
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Recommendation
Update the word-wrap package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.4
- Patched version(s): 1.2.4
References
Could your website be exposed too?
SmartScanner can check your website for word-wrap vulnerable to Regular Expression Denial of Service and gives you actionable findings to investigate.
Start a free scanRelated Issues
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
- angular vulnerable to regular expression denial of service via the $resource service - CVE-2023-26117
- angular vulnerable to regular expression denial of service via the angular.copy() utility - CVE-2023-26116
- angular vulnerable to regular expression denial of service (ReDoS) - CVE-2022-25844


