Asymmetric denial of service In npm-user-validate
Description
Regular expression denial of service in npm-user-validate This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.0.1 | ||
rpm rhel8 | 1:10.23.1-1.module+el8.3.0+9502+012d8a97 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.