nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Link | Tags |
---|---|
https://huntr.dev/bounties/a07b547a-f457-41c9-9d89-ee48bee8a4df | patch exploit third party advisory issue tracking |
https://github.com/daaku/nodejs-tmpl/commit/4c654e4d1542f329ed561fd95ccd80f30c6872d6 | third party advisory patch |