GHSA-pmvv-57rg-5g86

Suggest an improvement
Source
https://github.com/advisories/GHSA-pmvv-57rg-5g86
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pmvv-57rg-5g86
Aliases
  • CVE-2020-26305
Published
2024-10-26T21:30:46Z
Modified
2024-11-13T23:24:33Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 6.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green CVSS Calculator
Summary
CommonRegexJS Regular Expression Denial of Service vulnerability
Details

CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

Database specific
{
    "nvd_published_at": "2024-10-26T21:15:13Z",
    "cwe_ids": [
        "CWE-1333"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-28T14:44:58Z"
}
References

Affected packages

npm / commonregex

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json"