Marked ReDoS due to email addresses being evaluated in quadratic time
Moderate severity
GitHub Reviewed
Published
Jun 5, 2019
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Description
Reviewed
Jun 5, 2019
Published to the GitHub Advisory Database
Jun 5, 2019
Last updated
Jan 11, 2023
Versions of
marked
from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.Recommendation
Upgrade to version 0.6.2 or later.
References