{"id":"CVE-2020-28500","details":"Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.","aliases":["GHSA-29mw-wpgm-hmr9"],"modified":"2026-04-10T04:25:46.783836Z","published":"2021-02-15T11:15:12.397Z","related":["SNYK-JAVA-ORGFUJIONWEBJARS-1074896","SNYK-JAVA-ORGWEBJARS-1074894","SNYK-JAVA-ORGWEBJARSBOWER-1074892","SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895","SNYK-JAVA-ORGWEBJARSNPM-1074893","SNYK-JS-LODASH-1018905"],"references":[{"type":"WEB","url":"https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210312-0006/"},{"type":"ADVISORY","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"FIX","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"},{"type":"FIX","url":"https://github.com/lodash/lodash/pull/5065"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-LODASH-1018905"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lodash/lodash","events":[{"introduced":"0"},{"fixed":"c6e281b878b315c7a10d90f9c2af4cdb112d9625"},{"introduced":"0"},{"last_affected":"0847978784a28c9618a827e19220451e1eb5257f"},{"introduced":"0"},{"last_affected":"343b869a6880825a2397427668fbc64d82a060a6"},{"introduced":"0"},{"fixed":"506f585d78d236075f5d47b240518f3e1fdf5811"},{"introduced":"0"},{"last_affected":"506f585d78d236075f5d47b240518f3e1fdf5811"},{"introduced":"0"},{"last_affected":"2459a53350d3929600e0027542a7f5b61e180629"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"4.17.21"},{"introduced":"0"},{"last_affected":"3.2.0"},{"introduced":"0"},{"last_affected":"3.3.0"},{"introduced":"0"},{"fixed":"1.0"},{"introduced":"0"},{"last_affected":"1.0-NA"},{"introduced":"0"},{"last_affected":"1.0-sp1"}]}}],"versions":["0.1.0","0.10.0","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.5.0","0.5.1","0.5.2","0.6.0","0.6.1","0.7.0","0.8.0","0.8.1","0.8.2","0.9.0","0.9.1","0.9.2","1.0.0","1.0.0-rc.1","1.0.0-rc.2","1.0.0-rc.3","1.0.1","3.0.0-npm","3.0.0-npm-packages","3.0.1-npm","3.0.1-npm-packages","3.0.2-npm-packages","3.0.3-npm-packages","3.0.4-npm-packages","3.0.5-npm-packages","3.0.6-npm-packages","3.0.7-npm-packages","3.0.8-npm-packages","3.0.9-npm-packages","3.1.0-npm","3.1.0-npm-packages","3.1.1-npm-packages","3.1.2-npm-packages","3.1.3-npm-packages","3.1.4-npm-packages","3.1.5-npm-packages","3.1.6-npm-packages","3.1.7-npm-packages","3.10.0-npm","3.10.1-npm","3.2.0-npm","3.2.0-npm-packages","3.2.1-npm-packages","3.2.2-npm-packages","3.2.3-npm-packages","3.3.0-npm","3.3.0-npm-packages","3.3.1-npm","3.4.0-npm","3.5.0-npm","3.6.0-npm","3.7.0-npm","3.8.0-npm","3.9.0-npm","3.9.1-npm","3.9.2-npm","3.9.3-npm","4.0.0-npm","4.0.1-npm","4.1.0-npm","4.10.0-npm","4.11.0-npm","4.11.1-npm","4.11.2-npm","4.12.0-npm","4.13.0-npm","4.13.1-npm","4.14.0-npm","4.14.1-npm","4.14.2-npm","4.15.0-npm","4.16.0-npm","4.16.1-npm","4.16.2-npm","4.16.3-npm","4.16.4-npm","4.16.5-npm","4.16.6-npm","4.17.0-npm","4.17.1-npm","4.17.10-npm","4.17.11-npm","4.17.12-npm","4.17.13-npm","4.17.14-npm","4.17.15-npm","4.17.2-npm","4.17.20-npm","4.17.3-npm","4.17.4-npm","4.17.5-npm","4.17.9-npm","4.2.0-npm","4.2.1-npm","4.3.0-npm","4.4.0-npm","4.5.0-npm","4.5.1-npm","4.6.0-npm","4.6.1-npm","4.7.0-npm","4.8.0-npm","4.8.1-npm","4.8.2-npm","4.9.0-npm"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"14.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"14.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"1.11.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.4.2"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0.8.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0.8.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.2.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.0.0"}]},{"events":[{"introduced":"0"},{"fixed":"9.2.6.1"}]},{"events":[{"introduced":"0"},{"last_affected":"8.58"}]},{"events":[{"introduced":"0"},{"last_affected":"8.59"}]},{"events":[{"introduced":"17.12.0"},{"last_affected":"17.12.11"}]},{"events":[{"introduced":"18.8.0"},{"last_affected":"18.8.12"}]},{"events":[{"introduced":"19.12.0"},{"last_affected":"19.12.11"}]},{"events":[{"introduced":"20.12.0"},{"last_affected":"20.12.7"}]},{"events":[{"introduced":"17.7"},{"last_affected":"17.12"}]},{"events":[{"introduced":"0"},{"last_affected":"18.8"}]},{"events":[{"introduced":"0"},{"last_affected":"19.12"}]},{"events":[{"introduced":"0"},{"last_affected":"20.12"}]},{"events":[{"introduced":"0"},{"last_affected":"19.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28500.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}