VDB
Sign up
HIGH7.5

GHSA-f5w6-r7rg-mcgq

Regular Expression Denial of Service in validator

Quick fix

GHSA-f5w6-r7rg-mcgq — validator: upgrade to the fixed version with the command below.

npm install validator@3.22.1

Details

Versions of `validator` prior to 3.22.1 are affected by a regular expression denial of service vulnerability in the `isURL` method.

## Recommendation

Update to version 3.22.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/validator
Introduced in: 0Fixed in: 3.22.1
Fixnpm install validator@3.22.1

References