The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-FORMS-1296389 | third party advisory patch |
https://github.com/caolan/forms/pull/214 | third party advisory |
https://github.com/caolan/forms/pull/214/commits/d4bd5b5febfe49c1f585f162e04ec810f8dc47a0 | third party advisory patch |