Inefficient Regular Expression Complexity in vuelidate
High severity
GitHub Reviewed
Published
Sep 20, 2021
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Package
Affected versions
<= 2.0.0-alpha.21
Patched versions
2.0.0-alpha.22
Description
Published by the National Vulnerability Database
Sep 15, 2021
Reviewed
Sep 16, 2021
Published to the GitHub Advisory Database
Sep 20, 2021
Last updated
Jan 30, 2023
vuelidate is a simple, lightweight model-based validation for Vue.js 2.x & 3.0. A ReDoS (regular expression denial of service) flaw was found in the
@vuelidate/validators
package. An attacker that is able to provide crafted input to the url(input) function may cause an application to consume an excessive amount of CPU.References