CVE-2020-26303 – insane
Package
Manager: npm
Name: insane
Vulnerable Version: >=0 <=2.6.2
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
EPSS: 0.00261 pctl0.49274
Details
insane vulnerable to Regular Expression Denial of Service insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
Metadata
Created: 2024-10-26T21:30:46Z
Modified: 2024-11-13T23:24:39Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-w455-mfq9-hf74/GHSA-w455-mfq9-hf74.json
CWE IDs: ["CWE-1333"]
Alternative ID: GHSA-w455-mfq9-hf74
Finding: F211
Auto approve: 1