VDB
Sign up
LOW

GHSA-4x5v-gmq8-25ch

Regular expression denial of service in semver-regex

Quick fix

GHSA-4x5v-gmq8-25ch — semver-regex: upgrade to the fixed version with the command below.

npm install semver-regex@3.1.4

Details

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/semver-regex
Introduced in: 0Fixed in: 3.1.4
Fixnpm install semver-regex@3.1.4
npm/semver-regex
Introduced in: 4.0.0Fixed in: 4.0.3
Fixnpm install semver-regex@4.0.3

References