Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.
Upgrade to Loofah >= 2.19.1.
The Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1).
This vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).
{
"cwe_ids": [
"CWE-1333"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-13T17:36:28Z",
"severity": "HIGH",
"nvd_published_at": "2022-12-14T14:15:00Z"
}