VDB
KO
HIGH

GHSA-36jr-mh4h-2g58

d3-color vulnerable to ReDoS

Quick fix

GHSA-36jr-mh4h-2g58 — d3-color: upgrade to the fixed version with the command below.

npm install d3-color@3.1.0

Details

The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / d3-color
Introduced in: 1.0.2 Fixed in: 3.1.0
Fix npm install d3-color@3.1.0

References