QID 982611
QID 982611: Nodejs (npm) Security Update for npm-user-validate (GHSA-pw54-mh39-w3hc)
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pw54-mh39-w3hc for updates pertaining to this vulnerability.
Vendor References
- GHSA-pw54-mh39-w3hc -
github.com/advisories/GHSA-pw54-mh39-w3hc
CVEs related to QID 982611
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pw54-mh39-w3hc | npm-user-validate |
|