Description
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Recommendation
Update the word-wrap package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.4
- Patched version(s): 1.2.4
References
Related Issues
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
- angular vulnerable to regular expression denial of service via the $resource service - CVE-2023-26117
- angular vulnerable to regular expression denial of service via the angular.copy() utility - CVE-2023-26116
- angular vulnerable to regular expression denial of service (ReDoS) - CVE-2022-25844
You might also like:
- Tags:
- npm
- word-wrap
Anything's wrong? Let us know Last updated on February 13, 2025


