Regular Expression Denial of Service (ReDoS)
High severity
GitHub Reviewed
Published
Mar 19, 2021
to the GitHub Advisory Database
•
Updated Sep 21, 2023
Package
Affected versions
>= 5.2.2, < 6.0.2
>= 7.0.0, < 7.1.1
= 8.0.0
Patched versions
6.0.2
7.1.1
8.0.1
Description
Published by the National Vulnerability Database
Mar 12, 2021
Reviewed
Mar 15, 2021
Published to the GitHub Advisory Database
Mar 19, 2021
Last updated
Sep 21, 2023
npm
ssri
5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.References