Regular Expression Denial of Service (ReDoS) Affecting ansi2html package, versions *
Threat Intelligence
EPSS
0.12% (48th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID npm:ansi2html:20151025
- published 6 Nov 2015
- disclosed 25 Oct 2015
- credit Adam Baldwin
Introduced: 25 Oct 2015
CVE-2015-9239 Open this link in a new tabOverview
ansi2html
does not control the length of the input it processes, and uses regular expressions to parse it. As a result, it is susceptible to a Regular expression Denial of Service (ReDoS) vulnerabilities, rendering an application unavailable if a long or complex input is passed in.
CVSS Scores
version 3.1