QID 980768
QID 980768: Nodejs (npm) Security Update for url-regex (GHSA-v4rh-8p82-6h5w)
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v4rh-8p82-6h5w for updates pertaining to this vulnerability.
Vendor References
- GHSA-v4rh-8p82-6h5w -
github.com/advisories/GHSA-v4rh-8p82-6h5w
CVEs related to QID 980768
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v4rh-8p82-6h5w | url-regex |
|