Lucene search

K
nodejsAnonymousNODEJS:1701
HistoryMay 10, 2021 - 6:48 p.m.

Regular Expression Denial of Service

2021-05-1018:48:49
Anonymous
www.npmjs.com
24
vulnerable
regular expression denial of service
dat.gui
recommendation
cve-2020-7755
github advisory
rgb
rgba
redos
craft
safe version

EPSS

0.001

Percentile

45.7%

Overview

All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.

Recommendation

Avoid using dat.gui as there is no current safe version of this module

References

EPSS

0.001

Percentile

45.7%