GHSA-q75g-2496-mxpp
Dashboard / Vulnerabilities / GHSA-q75g-2496-mxpp
Summary: Regular Expression Denial of Service in parsejson
Details: Affected versions of `parsejson` are vulnerable to a regular expression denial of service when parsing untrusted user input. ## Recommendation The `parsejson` package has not been functionally updated since it was initially released. Additionally, it provides functionality which is natively included in Node.js, and therefore the native `JSON.parse()` should be used, for both performance and security reasons.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16113, https://github.com/get/parsejson/issues/4, https://github.com/advisories/GHSA-q75g-2496-mxpp, https://www.npmjs.com/advisories/528
Affected packages
Package
Name: parsejson
Purl: pkg:npm/parsejson
Affected ranges
Type: SEMVER
Events:
