Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

Regular Expression Denial of Service in Handlebars

GHSA-62gr-4qp9-h98f · CVE-2019-20922

Published · Modified

Description

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

Ready to move

Start Securing

Free, no credit card | First findings in minutes