MEDIUM5.3
GHSA-4hpf-3wq7-5rpr
Regular expression deinal of service (ReDoS) in is-my-json-valid
Quick fix
GHSA-4hpf-3wq7-5rpr — is-my-json-valid: upgrade to the fixed version with the command below.
npm install is-my-json-valid@2.17.2Details
It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-1107[ADVISORY]
- https://github.com/mafintosh/is-my-json-valid/pull/159[WEB]
- https://github.com/mafintosh/is-my-json-valid/commit/b3051b277f7caa08cd2edc6f74f50aeda65d2976[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1546357[WEB]
- https://snyk.io/vuln/npm:is-my-json-valid:20180214[WEB]