CVE-2020-26305

CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:talyssonoc:commonregexjs:*:*:*:*:*:node.js:*:*

History

13 Nov 2024, 20:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:talyssonoc:commonregexjs:*:*:*:*:*:node.js:*:*
First Time Talyssonoc
Talyssonoc commonregexjs
References () https://github.com/talyssonoc/CommonRegexJS/issues/4 - () https://github.com/talyssonoc/CommonRegexJS/issues/4 - Issue Tracking, Third Party Advisory
References () https://securitylab.github.com/advisories/GHSL-2020-291-redos-CommonRegexJS/ - () https://securitylab.github.com/advisories/GHSL-2020-291-redos-CommonRegexJS/ - Third Party Advisory

26 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-26 21:15

Updated : 2024-11-13 20:00


NVD link : CVE-2020-26305

Mitre link : CVE-2020-26305


JSON object : View

Products Affected

talyssonoc

  • commonregexjs
CWE
CWE-1333

Inefficient Regular Expression Complexity