VYPR
High severityGHSA Advisory· Published Aug 31, 2020· Updated Sep 23, 2021

Regular Expression Denial of Service in validator

CVE-2014-8882

Description

Versions of validator prior to 3.22.1 are affected by a regular expression denial of service vulnerability in the isURL method.

Recommendation

Update to version 3.22.1 or later.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
validatornpm
< 3.22.13.22.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.