Lucene search

K
osvGoogleOSV:GHSA-J377-2X76-558H
HistoryDec 10, 2021 - 5:25 p.m.

Improper Input Validation in is-email

2021-12-1017:25:21
Google
osv.dev
11
improper input validation
redos flaw
is-email package
node.js
cpu consumption
crafted input
software

EPSS

0.001

Percentile

45.6%

is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.

EPSS

0.001

Percentile

45.6%

Related for OSV:GHSA-J377-2X76-558H