Описание
uri-template-lite Regular Expression Denial of Service
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method.
Пакеты
Наименование
uri-template-lite
npm
Затронутые версииВерсия исправления
< 22.9.0
22.9.0
Связанные уязвимости
CVSS3: 5.9
nvd
больше 3 лет назад
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method