Lucene search

K
nodejsAnonymousNODEJS:1751
HistoryJun 07, 2021 - 9:57 p.m.

Regular expression denial of service

2021-06-0721:57:10
Anonymous
www.npmjs.com
208

0.012 Low

EPSS

Percentile

85.6%

Overview

glob-parent before 5.1.2 has a regular expression denial of service vulnerability. The enclosure regex used to check for strings ending in enclosure containing path separator.

Recommendation

Upgrade to version 5.1.2 or later

References

CPENameOperatorVersion
glob-parentlt5.1.2