{"id":"GHSA-7f53-fmmv-mfjv","summary":"Regular expression denial of service in react-native","details":"A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.","aliases":["CVE-2020-1920"],"modified":"2023-11-08T04:02:45.376849Z","published":"2021-07-20T17:33:28Z","database_specific":{"github_reviewed_at":"2021-06-02T19:22:39Z","nvd_published_at":"2021-06-01T14:15:00Z","cwe_ids":["CWE-400","CWE-697"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1920"},{"type":"WEB","url":"https://github.com/facebook/react-native/commit/ca09ae82715e33c9ac77b3fa55495cf84ba891c7"},{"type":"WEB","url":"https://github.com/facebook/react-native/releases/tag/v0.62.3"},{"type":"WEB","url":"https://github.com/facebook/react-native/releases/tag/v0.64.1"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2020-293-redos-react-native"},{"type":"WEB","url":"https://www.npmjs.com/package/react-native"}],"affected":[{"package":{"name":"react-native","ecosystem":"npm","purl":"pkg:npm/react-native"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.59.0"},{"fixed":"0.62.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-7f53-fmmv-mfjv/GHSA-7f53-fmmv-mfjv.json"}},{"package":{"name":"react-native","ecosystem":"npm","purl":"pkg:npm/react-native"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.63.0"},{"fixed":"0.64.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-7f53-fmmv-mfjv/GHSA-7f53-fmmv-mfjv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}