{"id":"GHSA-4wf5-vphf-c2xc","summary":"Terser insecure use of regular expressions leads to ReDoS","details":"The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.","aliases":["CVE-2022-25858"],"modified":"2025-01-14T10:57:13.174999Z","published":"2022-07-16T00:00:20Z","database_specific":{"nvd_published_at":"2022-07-15T20:15:00Z","cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-20T01:21:59Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25858"},{"type":"WEB","url":"https://github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76b"},{"type":"WEB","url":"https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012"},{"type":"PACKAGE","url":"https://github.com/terser/terser"},{"type":"WEB","url":"https://github.com/terser/terser/blob/master/lib/compress/evaluate.js%23L135"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949722"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-TERSER-2806366"}],"affected":[{"package":{"name":"terser","ecosystem":"npm","purl":"pkg:npm/terser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-4wf5-vphf-c2xc/GHSA-4wf5-vphf-c2xc.json"}},{"package":{"name":"terser","ecosystem":"npm","purl":"pkg:npm/terser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.14.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-4wf5-vphf-c2xc/GHSA-4wf5-vphf-c2xc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}