VDB
Sign up
MEDIUM6.5

GHSA-65p8-3hm4-h9h8

Denial of Service in rgb2hex

Quick fix

GHSA-65p8-3hm4-h9h8 — rgb2hex: upgrade to the fixed version with the command below.

npm install rgb2hex@0.1.6

Details

All versions of `rgb2hex` are vulnerable to Regular Expression Denial of Service (ReDoS) when an attacker can pass in a specially crafted invalid color value.

## Recommendation

Update to version 0.1.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rgb2hex
Introduced in: 0Fixed in: 0.1.6
Fixnpm install rgb2hex@0.1.6

References