GHSA-x4c5-c7rf-jjgv
MODERATECVE-2025-25285By crafting specific options parameters, the endpoint.parse(options) call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization.
- Affected
- >= 9.0.5, < 9.0.6
- Fixed in
- 9.0.6
- Weakness
- CWE-1333
- Published
- 2025-02-14
- Source
- github