Versions of validator prior to 3.22.1 are affected by a regular expression denial of service vulnerability in the isURL method.
Update to version 3.22.1 or later.
{
"github_reviewed_at": "2020-08-31T18:08:58Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": true
}