Lucene search

K
nodejsAnonymousNODEJS:1755
HistoryJun 08, 2021 - 11:12 p.m.

Regular Expression Denial of Service

2021-06-0823:12:07
Anonymous
www.npmjs.com
42

0.001 Low

EPSS

Percentile

43.3%

Overview

normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.

Recommendation

Upgrade to versions 4.5.1, 5.3.1, 6.0.1 or later

References