@fastify/swagger is vulnerable to Regular Expression Denial of Service (ReDoS)
25
Low Risk
The affected versions use a regular expression with potentially polynomial worst-case computational complexity, leading to excessive CPU consumption and possibly causing a Denial of Service (DoS). This vulnerability is located in the resolveServerUrls function.
You are affected if you are using a version that falls within the vulnerable range.
@fastify/swagger is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 8.1.0 - 8.12.0.
Upgrade the @fastify/swagger library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant