GHSA-vvf2-ppj9-pp49
Dashboard / Vulnerabilities / GHSA-vvf2-ppj9-pp49
Summary: Inefficient Regular Expression Complexity in vuelidate
Details: vuelidate is a simple, lightweight model-based validation for Vue.js 2.x & 3.0. A ReDoS (regular expression denial of service) flaw was found in the `@vuelidate/validators` package. An attacker that is able to provide crafted input to the url(input) function may cause an application to consume an excessive amount of CPU.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-3794, https://github.com/vuelidate/vuelidate/commit/1f0ca31c30e5032f00dbd14c4791b5ee7928f71d, https://github.com/vuelidate/vuelidate, https://huntr.dev/bounties/d8201b98-fb91-4c12-a6f7-181b4a20d9b7
Affected packages
Package
Name: @vuelidate/validators
Purl: pkg:npm/%40vuelidate/validators
Affected ranges
Type: SEMVER
Events:
