Intel

AIKIDO-2024-10413

nope-validator is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2020-26309 Published Nov 5, 2024

68

Medium Risk

This Affects:

jsnope-validator
0.2.0 - 0.11.3
Fixed in 0.12.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expressions in the consts.ts file. These regular expressions can be exploited by attackers to cause excessive backtracking, leading to performance degradation or a denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nope-validator is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.2.0 - 0.11.3.

How to fix this

Upgrade the nope-validator library to the patch version.