Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35860
HistoryJun 03, 2022 - 9:04 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-06-0309:04:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

0.001 Low

EPSS

Percentile

37.0%

semver-regex is vulnerable to regular expression denial of service. The vulnerability exists in semverRegex function in index.js due to improper use of regular expressions which allows an attacker to cause a ReDos.

0.001 Low

EPSS

Percentile

37.0%