@vendure/core is vulnerable to Inefficient Regular Expression Complexity
48
Medium Risk
Affected versions of the package are vulnerable to inefficient regular expression complexity. The email validation process uses a regex with exponential complexity, making it susceptible to ReDoS (Regular Expression Denial of Service) attacks when handling maliciously crafted inputs.
You are affected if you are using a version that falls within the vulnerable range.
@vendure/core is vulnerable to Inefficient Regular Expression Complexity in versions 2.1.3 - 3.0.3.
Upgrade the @vendure/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant