Lucene search

K
osvGoogleOSV:GHSA-VX3P-948G-6VHQ
HistoryMar 19, 2021 - 9:24 p.m.

Regular Expression Denial of Service (ReDoS)

2021-03-1921:24:36
Google
osv.dev
31

0.002 Low

EPSS

Percentile

64.5%

npm ssri 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

CPENameOperatorVersion
ssrilt7.1.1
ssrige7.0.0
ssrieq8.0.0
ssrige5.2.2
ssrilt6.0.2