@octokit/endpoint is vulnerable to Regular Expression Denial of Service (ReDoS)
71
High Risk
Affected versions of this package improperly handle user-controlled input when parsing headers for /graphql endpoints or URL objects in general. This can lead to excessive backtracking in regular expressions, making the application vulnerable to Regular expression Denial of Service (ReDoS). Attackers can exploit this by sending specially crafted inputs that trigger high computational overhead, potentially causing severe performance degradation, system outages, or denial of service.
You are affected if you are using a version that falls within the vulnerable range.
@octokit/endpoint is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.1.0 - 9.0.5 and 10.0.0 - 10.1.2.
Upgrade the @octokit/endpoint library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant