VDB
Sign up
MEDIUM5.3

GHSA-c56f-grv3-gpfr

Regular expression denial of service in forms

Quick fix

GHSA-c56f-grv3-gpfr — forms: upgrade to the fixed version with the command below.

npm install forms@1.3.2

Details

The package forms before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/forms
Introduced in: 0Fixed in: 1.3.2
Fixnpm install forms@1.3.2

References