Lucene search

K
osvGoogleOSV:GHSA-43F8-2H32-F4CJ
HistoryMay 06, 2021 - 4:10 p.m.

Regular Expression Denial of Service in hosted-git-info

2021-05-0616:10:39
Google
osv.dev
13

0.003 Low

EPSS

Percentile

70.8%

The npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity