QID 983996
QID 983996: Nodejs (npm) Security Update for slug (GHSA-jxqq-cqm6-pfq9)
Affected versions of `slug` are vulnerable to a regular expression denial of service when parsing untrusted user input. The issue is low severity, as it takes 50,000 characters to cause the event loop to block for 2 seconds, About 50k characters can block the event loop for 2 seconds. ## Recommendation Update to version 0.9.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jxqq-cqm6-pfq9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-jxqq-cqm6-pfq9 -
github.com/advisories/GHSA-jxqq-cqm6-pfq9
CVEs related to QID 983996
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jxqq-cqm6-pfq9 | slug |
|