Asymmetric denial of service In normalize-url
Description
ReDoS in normalize-url The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 11.8.1+~cs53.13.17-3 | ||
npm | 4.5.1, 5.3.1, 6.0.1 | ||
debian 14 | 11.8.1+~cs53.13.17-3 | ||
debian 13 | 11.8.1+~cs53.13.17-3 | ||
rpm rhel8 | 1:14.18.2-2.module+el8.5.0+13644+8d46dafd | ||
rpm rhel8.4 | 1:14.18.2-2.module+el8.4.0+13643+6c0ebf22 | ||
rpm rhel8 | - | - | |
rpm rhel9 | 0:2.0.19-1.el9_0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.