-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ReDoS in isHSL #1598
Comments
This is the regex affected, the second one does not suffer of this problem Line 4 in 1b85829
|
You're right. |
Sorry for the late ACK, I should work on a fix for this, this weekend before our release. Thanks for raising! |
fixed in #1651 |
This was referenced Oct 28, 2021
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Describe the bug
It allows cause a Regular Expression Denial of Service (REDoS) when checking if the crafted string is a hsl.
Examples
Additional context
Validator.js version: 14.10.0
Node.js version:
OS platform: windows
The text was updated successfully, but these errors were encountered: