MEDIUM5.3
GHSA-hgpf-97c5-74fc
Regular expression denial of service in @absolunet/kafe
Quick fix
GHSA-hgpf-97c5-74fc — @absolunet/kafe: upgrade to the fixed version with the command below.
npm install @absolunet/kafe@3.2.10Details
This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7761[ADVISORY]
- https://github.com/absolunet/kafe/commit/c644c798bfcdc1b0bbb1f0ca59e2e2664ff3fdd0%23diff-f0f4b5b19ad46588ae9d7dc1889f681252b0698a4ead3a77b7c7d127ee657857[WEB]
- https://snyk.io/vuln/SNYK-JS-ABSOLUNETKAFE-1017403[WEB]
- https://www.npmjs.com/package/@absolunet/kafe[WEB]