VDB
Sign up
HIGH7.5

GHSA-vx3p-948g-6vhq

Regular Expression Denial of Service (ReDoS)

Quick fix

GHSA-vx3p-948g-6vhq — ssri: upgrade to the fixed version with the command below.

npm install ssri@6.0.2

Details

npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ssri
Introduced in: 5.2.2Fixed in: 6.0.2
Fixnpm install ssri@6.0.2
npm/ssri
Introduced in: 7.0.0Fixed in: 7.1.1
Fixnpm install ssri@7.1.1
npm/ssri
Introduced in: 8.0.0Fixed in: 8.0.1
Fixnpm install ssri@8.0.1

References