Lucene search

K
osvGoogleOSV:GHSA-X6FG-F45M-JF5Q
HistoryOct 24, 2017 - 6:33 p.m.

Regular Expression Denial of Service in semver

2017-10-2418:33:36
Google
osv.dev
9

EPSS

0.002

Percentile

64.5%

Versions 4.3.1 and earlier of semver are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.

Recommendation

Update to version 4.3.2 or later