git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Link | Tags |
---|---|
https://gist.github.com/6en6ar/7c2424c93e7fbf2b6fc44e7fb9acb95d | third party advisory exploit |