VDB
Sign up
HIGH7.5

GHSA-v4rh-8p82-6h5w

Regular expression denial of service in url-regex

Details

all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-regex
Introduced in: 0

No fixed version published yet for url-regex (npm). Pin to a known-safe version or switch to an alternative.

References