HIGH7.5
GHSA-v6wh-2wvh-c8x5
Regular Expression Denial of Service in djvalidator
Details
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, `--@------------------------------------------------------------------------------------------------------------------------!`.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/djvalidator
Introduced in:
0No fixed version published yet for djvalidator (npm). Pin to a known-safe version or switch to an alternative.