GHSA-hj48-42vr-x3v9
MODERATECVE-2021-23343Affected versions of npm package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.
- Affected
- < 1.0.7
- Fixed in
- 1.0.7
- Weakness
- CWE-400
- Published
- 2021-08-10
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference