VDB
Sign up
HIGH7.5

GHSA-8h55-q5qq-p685

(ReDoS) Regular Expression Denial of Service in tf2-item-format

Quick fix

GHSA-8h55-q5qq-p685 — tf2-item-format: upgrade to the fixed version with the command below.

npm install tf2-item-format@5.9.14

Details

## Summary

Versions of `tf2-item-format` since at least `4.2.6` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input.

## Tested Versions

- `5.9.13` - `5.8.10` - `5.7.0` - `5.6.17` - `4.3.5` - `4.2.6`

### v5 Upgrade package to `^5.9.14`

### v4 No patch exists. Please consult the [v4 to v5 migration guide](https://github.com/danocmx/node-tf2-item-format?tab=readme-ov-file#migrating-from-v4-to-v5) to upgrade to v5.

If upgrading to v5 is not possible, fork the module repository and implement the fix detailed below.

## Impact

This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tf2-item-format
Introduced in: 4.2.6Fixed in: 5.9.14
Fixnpm install tf2-item-format@5.9.14

References