Lucene search

K
nodejsAnonymousNODEJS:1677
HistoryMay 06, 2021 - 4:15 p.m.

Regular Expression Denial of Service

2021-05-0616:15:08
Anonymous
www.npmjs.com
42

0.003 Low

EPSS

Percentile

70.9%

Overview

hosted-git-info before versions 2.8.9 and 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity

Recommendation

Upgrade to version 3.0.8 or later

References