MEDIUM5.3
GHSA-xx4c-jj58-r7x6
Inefficient Regular Expression Complexity in Validator.js
Quick fix
GHSA-xx4c-jj58-r7x6 — validator: upgrade to the fixed version with the command below.
npm install validator@13.7.0Details
### Impact Versions of `validator` prior to 13.7.0 are affected by an inefficient Regular Expression complexity when using the `rtrim` and `trim` sanitizers.
### Patches The problem has been patched in validator 13.7.0
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/validatorjs/validator.js/security/advisories/GHSA-xx4c-jj58-r7x6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-3765[ADVISORY]
- https://github.com/validatorjs/validator.js/issues/1599[WEB]
- https://github.com/validatorjs/validator.js/pull/1738[WEB]
- https://github.com/validatorjs/validator.js[PACKAGE]
- https://huntr.dev/bounties/c37e975c-21a3-4c5f-9b57-04d63b28cfc9[WEB]