{"id":"GHSA-325j-24f4-qv5x","summary":"Regular Expression Denial of Service in ssri","details":"Version of `ssri` prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.\n\n\n## Recommendation\n\nUpdate to version 5.2.2 or later.","aliases":["CVE-2018-7651"],"modified":"2023-11-08T04:00:23.259650Z","published":"2018-03-07T22:22:20Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:53:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7651"},{"type":"WEB","url":"https://github.com/zkat/ssri/issues/10"},{"type":"WEB","url":"https://github.com/zkat/ssri/commit/d0ebcdc22cb5c8f47f89716d08b3518b2485d65d"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-325j-24f4-qv5x"},{"type":"PACKAGE","url":"https://github.com/zkat/ssri"},{"type":"WEB","url":"https://www.npmjs.com/advisories/565"}],"affected":[{"package":{"name":"ssri","ecosystem":"npm","purl":"pkg:npm/ssri"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-325j-24f4-qv5x/GHSA-325j-24f4-qv5x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}