Asymmetric denial of service - ReDoS In browserslist
Description
Regular Expression Denial of Service in browserslist The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.16.5 | ||
debian 11 | 4.16.3+~cs5.4.72-2 | ||
debian 13 | 4.16.3+~cs5.4.72-2 | ||
debian 14 | 4.16.3+~cs5.4.72-2 | ||
debian 12 | 4.16.3+~cs5.4.72-2 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.