VDB
Sign up
MEDIUM5.9

GHSA-vp56-6g26-6827

node-fetch Inefficient Regular Expression Complexity

Quick fix

GHSA-vp56-6g26-6827 — node-fetch: upgrade to the fixed version with the command below.

npm install node-fetch@3.2.10

Details

[node-fetch](https://www.npmjs.com/package/node-fetch) is a light-weight module that brings window.fetch to node.js.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the `isOriginPotentiallyTrustworthy()` function in `referrer.js`, when processing a URL string with alternating letters and periods, such as `'http://' + 'a.a.'.repeat(i) + 'a'`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-fetch
Introduced in: 3.0.0Fixed in: 3.2.10
Fixnpm install node-fetch@3.2.10

References