GHSA-8cv5-p934-3hwp
Denial of service in fast-csv
Quick fix
GHSA-8cv5-p934-3hwp — fast-csv: upgrade to the fixed version with the command below.
npm install fast-csv@4.3.6Details
### Impact Possible ReDoS (Regular Expression Denial of Service) when using `ignoreEmpty` option when parsing.
### Patches This has been patched in `v4.3.6`
### Workarounds You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6`
### References
This vulnerability was found using a [CodeQL](https://securitylab.github.com/tools/codeql) query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable. [Link to query run](https://lgtm.com/query/8609731774537641779/).
### For more information If you have any questions or comments about this advisory: * Open an issue in [fast-csv](https://github.com/C2FO/fast-csv)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/C2FO/fast-csv/security/advisories/GHSA-8cv5-p934-3hwp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-26256[ADVISORY]
- https://github.com/C2FO/fast-csv/issues/540[WEB]
- https://github.com/C2FO/fast-csv/commit/4bbd39f26a8cd7382151ab4f5fb102234b2f829e[WEB]
- https://github.com/C2FO/fast-csv[PACKAGE]
- https://lgtm.com/query/8609731774537641779[WEB]
- https://www.npmjs.com/advisories/1587[WEB]
- https://www.npmjs.com/advisories/1588[WEB]
- https://www.npmjs.com/package/@fast-csv/parse[WEB]
- https://www.npmjs.com/package/fast-csv[WEB]