PT-2024-10795 · Unknown · Commonregexjs

Erik Krogh Kristensen

·

Published

2024-10-26

·

Updated

2024-11-13

·

CVE-2020-26305

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Green
Name of the Vulnerable Software and Affected Versions CommonRegexJS versions all available versions
Description The issue concerns Regular Expression Denial of Service (ReDoS) due to vulnerable regular expressions in CommonRegexJS. No known patches are available as of the time of publication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

CVE-2020-26305
GHSA-PMVV-57RG-5G86

Affected Products

Commonregexjs