A vulnerability was discovered in IS-SVG version 4.3.1 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.
{
"cwe_ids": [
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2021-06-22T15:40:38Z",
"nvd_published_at": "2021-06-21T16:15:00Z",
"severity": "HIGH"
}