HIGH 7.5 npm

Regular Expression Denial of Service in semver

GHSA-x6fg-f45m-jf5q · CVE-2015-8855

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Versions 4.3.1 and earlier of semver are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.

Recommendation

Update to version 4.3.2 or later

Ready to move

Start Securing

Free, no credit card | First findings in minutes