Description
A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity. It is possible to initiate the attack remotely.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.5.1
References
Related Issues
- LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex - CVE-2026-45617
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge - CVE-2026-44495
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint - CVE-2026-42342
You might also like:
- Tags:
- npm
- js-video-url-parser
Anything's wrong? Let us know Last updated on April 10, 2026


