ZeroHour

CVE-2022-25858

PoC ×2
CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

Vendors
terser
Products
terser
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.