HIGH7.5
GHSA-pfq8-rq6v-vf5m
kangax html-minifier REDoS vulnerability
Details
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/html-minifier
Introduced in:
0No fixed version published yet for html-minifier (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37620[ADVISORY]
- https://github.com/kangax/html-minifier/issues/1135[WEB]
- https://github.com/kangax/html-minifier[PACKAGE]
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L1338[WEB]
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L294[WEB]
- https://security.snyk.io/vuln/SNYK-JS-HTMLMINIFIER-3091181[WEB]