VDB
Sign up
HIGH7.5

GHSA-xfhp-gmh8-r8v2

printf vulnerable to Regular Expression Denial of Service (ReDoS)

Quick fix

GHSA-xfhp-gmh8-r8v2 — printf: upgrade to the fixed version with the command below.

npm install printf@0.6.1

Details

The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string ```regex /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g ``` in `lib/printf.js`. The vulnerable regular expression has cubic worst-case time complexity.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/printf
Introduced in: 0Fixed in: 0.6.1
Fixnpm install printf@0.6.1

References