A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://github.com/segmentio/is-email/releases | third party advisory release notes |
https://segment.com/docs/release_notes/2021-07-13-cve-2021-36716/ | vendor advisory |