Certain configurations of rails-html-sanitizer < 1.4.4
use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.
Upgrade to rails-html-sanitizer >= 1.4.4
.
The maintainers have evaluated this as High Severity 7.5 (CVSS3.1).
This vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).
{ "nvd_published_at": "2022-12-14T17:15:00Z", "cwe_ids": [ "CWE-1333" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-12-13T17:43:02Z" }