High severity7.5NVD Advisory· Published Dec 22, 2022· Updated Jun 17, 2026
CVE-2020-26302
CVE-2020-26302
Description
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can cause the regex to loop “forever." This vulnerability was found using a CodeQL query which identifies inefficient regular expressions. is.js has no patch for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
is_jsnpm | <= 0.9.0 | — |
Affected products
3- Range: 0.9.0
Patches
Vulnerability mechanics
References
4- securitylab.github.com/advisories/GHSL-2020-295-redos-is.jsnvdExploitThird Party AdvisoryADVISORY
- github.com/advisories/GHSA-pvrw-g6fx-mcx2ghsaADVISORY
- github.com/arasatasaygin/is.js/issues/320nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-26302ghsaADVISORY
News mentions
0No linked articles in our index yet.