@boundaries/elements is vulnerable to Inefficient Regular Expression Complexity
25
Low Risk
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the HANDLEBARS_TEMPLATE_REGEX due to an inefficient regex pattern. Attackers can exploit this by crafting malicious Handlebars templates that cause catastrophic backtracking, leading to excessive CPU consumption and service disruption. This vulnerability allows denial of service attacks by triggering exponential time complexity in regex matching, potentially rendering the application unresponsive.
You are affected if you are using a version that falls within the vulnerable range.
@boundaries/elements is vulnerable to Inefficient Regular Expression Complexity in versions 1.1.0 - 1.1.1.
Upgrade the @boundaries/elements library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant