VDB
Sign up
LOW3.7

GHSA-gxpj-cx7g-858c

Regular Expression Denial of Service in debug

Quick fix

GHSA-gxpj-cx7g-858c — debug: upgrade to the fixed version with the command below.

npm install debug@2.6.9

Details

Affected versions of `debug` are vulnerable to regular expression denial of service when untrusted user input is passed into the `o` formatter.

As it takes 50,000 characters to block the event loop for 2 seconds, this issue is a low severity issue.

This was later re-introduced in version v3.2.0, and then repatched in versions 3.2.7 and 4.3.1.

## Recommendation

Version 2.x.x: Update to version 2.6.9 or later. Version 3.1.x: Update to version 3.1.0 or later. Version 3.2.x: Update to version 3.2.7 or later. Version 4.x.x: Update to version 4.3.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/debug
Introduced in: 0Fixed in: 2.6.9
Fixnpm install debug@2.6.9
npm/debug
Introduced in: 3.0.0Fixed in: 3.1.0
Fixnpm install debug@3.1.0
npm/debug
Introduced in: 3.2.0Fixed in: 3.2.7
Fixnpm install debug@3.2.7
npm/debug
Introduced in: 4.0.0Fixed in: 4.3.1
Fixnpm install debug@4.3.1

References