Lucene search

K
nodejsAnonymousNODEJS:1773
HistoryAug 10, 2021 - 3:59 p.m.

Regular Expression Denial of Service in path-parse

2021-08-1015:59:47
Anonymous
www.npmjs.com
133

0.003 Low

EPSS

Percentile

68.7%

Overview

Affected versions of path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

Recommendation

Upgrade to version 1.0.7 or later

References

CPENameOperatorVersion
path-parselt1.0.7