Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1xam03LTU1dnYtM2M1Zs4AAxDO

mel-spintax has Inefficient Regular Expression Complexity

A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/spintax.js. The manipulation of the argument text leads to inefficient regular expression complexity. The name of the patch is 37767617846e27b87b63004e30216e8f919637d3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218456.

Permalink: https://github.com/advisories/GHSA-qjm7-55vv-3c5f
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xam03LTU1dnYtM2M1Zs4AAxDO
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: over 1 year ago


Identifiers: GHSA-qjm7-55vv-3c5f, CVE-2018-25077
References: Repository: https://github.com/melnaron/mel-spintax
Blast Radius: 0.0

Affected Packages

npm:mel-spintax
Dependent packages: 3
Dependent repositories: 11
Downloads: 304 last month
Affected Version Ranges: < 1.0.3
Fixed in: 1.0.3
All affected versions: 1.0.0, 1.0.1, 1.0.2
All unaffected versions: 1.0.3, 1.0.4