Regular Expression Denial of Service in uglify-js
High severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Apr 11, 2023
Versions of
uglify-js
prior to 2.6.0 are affected by a regular expression denial of service vulnerability when malicious inputs are passed into theparse()
method.Proof of Concept
Results
Recommendation
Update to version 2.6.0 or later.
References