{"id":"GHSA-x5rq-j2xg-h7qm","summary":"Regular Expression Denial of Service (ReDoS) in lodash","details":"lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.","aliases":["CVE-2019-1010266"],"modified":"2026-03-13T21:56:22.446078Z","published":"2019-07-19T16:13:07Z","database_specific":{"severity":"MODERATE","nvd_published_at":null,"cwe_ids":["CWE-400"],"github_reviewed_at":"2019-07-19T16:11:26Z","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010266"},{"type":"WEB","url":"https://github.com/lodash/lodash/issues/3359"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/6138"},{"type":"WEB","url":"https://github.com/lodash/lodash/commit/5c08f18d365b64063bfbfa686cbb97cdd6267347"},{"type":"PACKAGE","url":"https://github.com/lodash/lodash"},{"type":"WEB","url":"https://github.com/lodash/lodash/wiki/Changelog"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-1010266.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190919-0004"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-LODASH-73639"}],"affected":[{"package":{"name":"lodash","ecosystem":"npm","purl":"pkg:npm/lodash"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.7.0"},{"fixed":"4.17.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-x5rq-j2xg-h7qm/GHSA-x5rq-j2xg-h7qm.json"}},{"package":{"name":"lodash-es","ecosystem":"npm","purl":"pkg:npm/lodash-es"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.7.0"},{"fixed":"4.17.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-x5rq-j2xg-h7qm/GHSA-x5rq-j2xg-h7qm.json"}},{"package":{"name":"lodash-amd","ecosystem":"npm","purl":"pkg:npm/lodash-amd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.7.0"},{"fixed":"4.17.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-x5rq-j2xg-h7qm/GHSA-x5rq-j2xg-h7qm.json"}},{"package":{"name":"lodash-rails","ecosystem":"RubyGems","purl":"pkg:gem/lodash-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.0"},{"fixed":"4.17.11"}]}],"versions":["4.11.2","4.12.0","4.13.1","4.14.1","4.15.0","4.16.1","4.16.3","4.16.4","4.16.6","4.17.10","4.17.2","4.17.4","4.17.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-x5rq-j2xg-h7qm/GHSA-x5rq-j2xg-h7qm.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}