Intel

AIKIDO-2024-10016

temporal-polyfill is vulnerable to Inefficient Regular Expression Complexity

Inefficient Regular Expression Complexity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 8, 2024

49

Medium Risk

This Affects:

JStemporal-polyfill
0.0.0 - 0.2.1
Fixed in 0.2.2
Are you affected? Scan for Free

TL;DR

The product uses a regular expression with inefficient, potentially exponential worst-case computational complexity, leading to excessive CPU usage.

Who does this affect?

You are affected if you are using a version of this package smaller or equal to 0.2.1.

Background info

temporal-polyfill is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 0.2.1.

How to fix this

Upgrade the temporal-polyfill library to the patch version.