all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://github.com/kevva/url-regex/issues/70 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JS-URLREGEX-569472 | third party advisory exploit |