Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31916
HistorySep 02, 2021 - 9:18 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-09-0209:18:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
98

0.019 Low

EPSS

Percentile

88.6%

axios is vulnerable to regular expression denial of service. The vulnerability exists in trim in utils.js due to inefficient regular expression complexity which allows an attacker to crash the application by submitting a malicious string as a header.

References