GHSA-xfhp-gmh8-r8v2
Dashboard / Vulnerabilities / GHSA-xfhp-gmh8-r8v2
GHSA-xfhp-gmh8-r8v2
Summary: printf vulnerable to Regular Expression Denial of Service (ReDoS)
Details: The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string ```regex /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g ``` in `lib/printf.js`. The vulnerable regular expression has cubic worst-case time complexity.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-23354, https://github.com/adaltas/node-printf/issues/31, https://github.com/adaltas/node-printf/pull/32, https://github.com/adaltas/node-printf/commit/a8502e7c9b0b22555696a2d8ef67722086413a68, https://snyk.io/vuln/SNYK-JS-PRINTF-1072096
Affected packages
Package
Name: printf
Purl: pkg:npm/printf
Affected ranges
Type: SEMVER
Events:
