z-schema is vulnerable to Regular Expression Denial-of-service (ReDoS)
55
Medium Risk
Affected versions of z-schema are vulnerable to a Regular Expression Denial of Service (ReDoS) due to unsafe regular expression handling in schema pattern validation. The implementation evaluates user-controlled schema patterns without verifying whether the supplied regex is safe, allowing crafted expressions with catastrophic backtracking to trigger excessive CPU consumption during validation. This may lead to application-level denial of service when processing malicious schemas or data.
You are affected if you are using a version that falls within the vulnerable range.
z-schema is vulnerable to Regular Expression Denial-of-service (ReDoS) in versions 7.1.0 - 12.0.4.
Upgrade the z-schema library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant