MEDIUM5.9
GHSA-vp56-6g26-6827
node-fetch Inefficient Regular Expression Complexity
Quick fix
GHSA-vp56-6g26-6827 — node-fetch: upgrade to the fixed version with the command below.
npm install node-fetch@3.2.10Details
[node-fetch](https://www.npmjs.com/package/node-fetch) is a light-weight module that brings window.fetch to node.js.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the `isOriginPotentiallyTrustworthy()` function in `referrer.js`, when processing a URL string with alternating letters and periods, such as `'http://' + 'a.a.'.repeat(i) + 'a'`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-2596[ADVISORY]
- https://github.com/node-fetch/node-fetch/pull/1611[WEB]
- https://github.com/node-fetch/node-fetch/commit/28802387292baee467e042e168d92597b5bbbe3d[WEB]
- https://github.com/node-fetch/node-fetch[PACKAGE]
- https://github.com/node-fetch/node-fetch/releases/tag/v3.2.10[WEB]
- https://huntr.dev/bounties/a7e6a136-0a4b-46c4-ad20-802f1dd60bf7[WEB]