Asymmetric denial of service - ReDoS In sanitize-html
Description
Sanitize-html Vulnerable To REDoS Attacks The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 2.7.1+~2.6.2-1 | ||
npm | 2.7.1 | ||
debian 14 | 2.7.1+~2.6.2-1 | ||
debian 12 | 2.7.1+~2.6.2-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2.