GHSA-582f-p4pg-xc74
HIGHCVE-2019-17592Versions of csv-parse prior to 4.4.6 are vulnerable to Regular Expression Denial of Service. The isInt() function contains a malformed regular expression that processes large specially-crafted input very slowly, leading to a Denial of Service. This is triggered when using the cast option.
- Affected
- < 4.4.6
- Fixed in
- 4.4.6
- Weakness
- CWE-20
- Published
- 2019-10-15
- Source
- github