Regular Expression Denial of Service (ReDoS) Affecting uri-js package, versions <3.0.0
Threat Intelligence
EPSS
0.07% (33rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID npm:uri-js:20160804
- published 16 Apr 2017
- disclosed 15 Mar 2016
- credit Peter Dotchev
Introduced: 15 Mar 2016
CVE-2017-16021 Open this link in a new tabHow to fix?
Upgrade uri-js
to version 3.0.0 or higher.
Overview
uri-js
is an RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when validating URLs.
CVSS Scores
version 3.1