Описание
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
Ссылки
- ProductRelease Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.51.5 (включая) до 5.55.7 (исключая)
cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 35%
0.00421
Низкий
7.5 High
CVSS3
Дефекты
CWE-1333
Связанные уязвимости
CVSS3: 5.9
redhat
2 месяца назад
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
EPSS
Процентиль: 35%
0.00421
Низкий
7.5 High
CVSS3
Дефекты
CWE-1333