QID 982609
QID 982609: Nodejs (npm) Security Update for express-validators (GHSA-cf2x-rqc8-grfq)
All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cf2x-rqc8-grfq for updates pertaining to this vulnerability.
Vendor References
- GHSA-cf2x-rqc8-grfq -
github.com/advisories/GHSA-cf2x-rqc8-grfq
CVEs related to QID 982609
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cf2x-rqc8-grfq | express-validators |
|