CVE List
-
CVE-2021-40901:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
scniro-validatorversionv1.0.1when validating crafted invalid emails. -
CVE-2021-40900:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
regexfnversionv1.0.5when validating crafted invalid emails. -
CVE-2021-40899:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
repo-git-downloaderversionv0.1.1when downloading crafted invalid git repositories. -
CVE-2021-40898:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
scaffold-helperversionv1.2.0when copying crafted invalid files. -
CVE-2021-40897:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
split-html-to-charsversionv1.0.5when splitting crafted invalid htmls. -
CVE-2021-40896:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
that-valueversionv0.1.3when validating crafted invalid emails. -
CVE-2021-40895:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
todo-regexversionv0.1.1when matching crafted invalid TODO statements. -
CVE-2021-40894:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
underscore-99xpversionv1.7.2when the deepValueSearch function is called. -
CVE-2021-40893:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
validate-dataversionv0.1.1when validating crafted invalid emails. -
CVE-2021-40892:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
validate-colorversionv2.1.0when handling crafted invalid rgb(a) strings. -
CVE-2021-23663:
All versions of package
seyare vulnerable to Prototype Pollution via thedeepmerge()function. -
CVE-2021-23561:
All versions of package
combare vulnerable to Prototype Pollution via thedeepMerge()function. -
CVE-2021-23797:
All versions of package
http-server-nodeare vulnerable to Directory Traversal via use of--path-as-is. -
CVE-2021-23700:
All versions of package
merge-deep2are vulnerable to Prototype Pollution via themergeDeep()function. -
CVE-2021-3801:
prismis vulnerable to Inefficient Regular Expression Complexity. -
CVE-2021-3810:
code-serveris vulnerable to Inefficient Regular Expression Complexity. -
CVE-2021-3795:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
semver-regexwhen formatting crafted invalid semver versions. -
CVE-2021-3803:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
nth-checkwhen parsing crafted invalid CSS nth-checks. -
CVE-2021-3807:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
ansi-regexwhen matching crafted invalid ANSI escape codes. -
CVE-2021-3765:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
validator.jswhen validating crafted invalid MagnetURIs. -
CVE-2021-3777:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
tmplversionv1.0.5when formatting crafted strings. -
CVE-2021-3733:
There's a flaw in
urllib's AbstractBasicAuthHandlerclass. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. -
CVE-2021-36716:
A ReDoS (regular expression denial of service) flaw was found in the Segment
is-emailpackage before1.0.1for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU. -
CVE-2021-23437:
The package
pillowfrom0and before8.3.2are vulnerable to Regular Expression Denial of Service (ReDoS) via thegetrgbfunction. -
CVE-2021-29063:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
Mpmathversionv1.0.0when thempmathifyfunction is called. -
CVE-2021-29061:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
Vfsjfilechooser2version0.2.9and below which occurs when the application attempts to validate craftedURIs. -
CVE-2021-29060:
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in
Color-Stringversion1.5.5and below which occurs when the application is provided and checks a crafted invalidHWBstring. -
CVE-2021-29059:
A vulnerability was discovered in
IS-SVGversion4.3.1and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalidSVGstring. -
CVE-2021-23392:
The package
locutusbefore2.0.15are vulnerable to Regular Expression Denial of Service (ReDoS) via thegopher_parsedirfunction. -
CVE-2021-23343:
All versions of package
path-parseare vulnerable to Regular Expression Denial of Service (ReDoS) viasplitDeviceRe,splitTailRe, andsplitPathReregular expressions. ReDoS exhibits polynomial worst-case time complexity. -
CVE-2021-23364:
The package
browserslistfrom4.0.0and before4.16.5are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. -
CVE-2021-23382:
The package
postcssbefore8.2.13are vulnerable to Regular Expression Denial of Service (ReDoS) viagetAnnotationURL()andloadAnnotation()inlib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern\/\*\s*# sourceMappingURL=(.*). -
CVE-2021-21391:
Affected versions of several
CKEditor 5packages are vulnerable to Regular Expression Denial of Service (ReDoS). It allows to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. -
CVE-2021-23368:
The package
postcssfrom7.0.0and before8.2.10are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing. -
CVE-2021-23362:
The package
hosted-git-infobefore3.0.8are vulnerable to Regular Expression Denial of Service (ReDoS) via the regular expressionshortcutMatchin thefromUrlfunction inindex.js. The affected regular expression exhibits polynomial worst-case time complexity. -
CVE-2021-27290:
ssri5.2.2-8.0.0, fixed in8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using thestrictoption. -
CVE-2021-23354:
The package
printfbefore0.6.1are vulnerable to Regular Expression Denial of Service (ReDoS) via the regexFormatter.prototype._reinlib/printf.js. The vulnerable regular expression has cubic worst-case time complexity. -
CVE-2021-23353:
This affects the package
jspdfbefore2.3.1. ReDoS is possible via theaddImagefunction. -
CVE-2021-23346:
This affects the package
html-parse-stringifybefore2.0.1; all versions of packagehtml-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process. -
CVE-2021-23341:
The package
prismjsbefore1.23.0are vulnerable to Regular Expression Denial of Service (ReDoS) via theprism-asciidoc,prism-rest,prism-tapandprism-eiffelcomponents. -
CVE-2021-21317:
uap-corein an open-source npm package which contains the core of BrowserScope's original user agent string parser. Inuap-corebefore version0.11.0, some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This is fixed in version0.11.0. Downstream packages such asuap-python,uap-rubyetc which depend uponuap-corefollow different version schemes. -
CVE-2020-29651:
A denial of service via regular expression in the
py.path.svnwccomponent ofpy(akapython-py) through1.9.0could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. -
CVE-2020-28500:
All versions of package
lodash; all versions of packageorg.fujion.webjars:lodashare vulnerable to Regular Expression Denial of Service (ReDoS) via thetoNumber,trimandtrimEndfunctions. -
CVE-2020-28496:
This affects the package
threebefore0.125.0. This can happen when handling rgb or hsl colors. -
CVE-2020-28493:
This affects the package
jinja2from0.0.0and before2.11.3. The ReDoS vulnerability is mainly due to the_punctuation_re regexoperator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory. -
CVE-2020-28469:
Affected versions of the package
glob-parentare vulnerable to Regular Expression Denial of Service (ReDoS). Theenclosureregex used to check for strings ending in enclosure containing path separator. -
CVE-2020-27511:
An issue was discovered in the
stripTagsandunescapeHTMLcomponents inPrototype1.7.3version1.6and below where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping craftedHTMLtags. -
CVE-2020-7793:
The package
ua-parser-jsbefore0.7.23are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes. -
CVE-2020-7779:
All versions of package
djvalidatorare vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails. -
CVE-2020-7767:
All versions of package
express-validatorsare vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls. -
CVE-2020-7761:
This affects the package
@absolunet/kafebefore3.2.10. It allows cause a denial of service when validating crafted invalid emails. -
CVE-2020-7760:
This affects the package
codemirrorbefore5.58.2; the packageorg.apache.marmotta.webjars:codemirrorbefore5.58.2. -
CVE-2020-7755:
All versions of package
dat.guiare vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values. -
CVE-2020-7754:
This affects the package
npm-user-validatebefore1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with@characters. -
CVE-2020-7753:
All versions of package
trimare vulnerable to Regular Expression Denial of Service (ReDoS) viatrim(). -
CVE-2020-7733:
The package
ua-parser-jsbefore0.7.22are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex forRedmi PhonesandMi Pad Tablets UA.
