VDB
Sign up
MEDIUM5.7

GHSA-8cv5-p934-3hwp

Denial of service in fast-csv

Quick fix

GHSA-8cv5-p934-3hwp — fast-csv: upgrade to the fixed version with the command below.

npm install fast-csv@4.3.6

Details

### Impact Possible ReDoS (Regular Expression Denial of Service) when using `ignoreEmpty` option when parsing.

### Patches This has been patched in `v4.3.6`

### Workarounds You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6`

### References

This vulnerability was found using a [CodeQL](https://securitylab.github.com/tools/codeql) query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable. [Link to query run](https://lgtm.com/query/8609731774537641779/).

### For more information If you have any questions or comments about this advisory: * Open an issue in [fast-csv](https://github.com/C2FO/fast-csv)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-csv
Introduced in: 0Fixed in: 4.3.6
Fixnpm install fast-csv@4.3.6
npm/@fast-csv/parse
Introduced in: 0Fixed in: 4.3.6
Fixnpm install @fast-csv/parse@4.3.6

References