logo

GHSA-g95f-p29q-9xw4 braces

Package

Manager: npm
Name: braces
Vulnerable Version: >=0 <2.3.1

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

Regular Expression Denial of Service in braces Versions of `braces` prior to 2.3.1 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service. ## Recommendation Upgrade to version 2.3.1 or higher.

Metadata

Created: 2019-06-06T15:30:30Z
Modified: 2021-08-04T21:35:07Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-g95f-p29q-9xw4/GHSA-g95f-p29q-9xw4.json
CWE IDs: ["CWE-185", "CWE-400"]
Alternative ID: N/A
Finding: F211
Auto approve: 1