VDB
Sign up
HIGH7.5

GHSA-cgfm-xwp7-2cvr

Sanitize-html Vulnerable To REDoS Attacks

Quick fix

GHSA-cgfm-xwp7-2cvr — sanitize-html: upgrade to the fixed version with the command below.

npm install sanitize-html@2.7.1

Details

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sanitize-html
Introduced in: 0Fixed in: 2.7.1
Fixnpm install sanitize-html@2.7.1

References