VDB
Sign up
LOW

GHSA-j9m2-h2pv-wvph

Regular expression denial of service in jquery-validation

Quick fix

GHSA-j9m2-h2pv-wvph — jquery-validation: upgrade to the fixed version with the command below.

npm install jquery-validation@1.19.4

Details

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery-validation
Introduced in: 0Fixed in: 1.19.4
Fixnpm install jquery-validation@1.19.4

References