Lucene search

K
osvGoogleOSV:GHSA-7R28-3M3F-R2PR
HistoryMar 19, 2021 - 9:25 p.m.

Regular Expression Denial of Service (ReDoS)

2021-03-1921:25:50
Google
osv.dev
15
node.js
is-svg package
redos
vulnerability
regex pattern
processing delay

EPSS

0.002

Percentile

59.2%

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input.

EPSS

0.002

Percentile

59.2%