7.5
CVE-2023-26115
- EPSS 0.05%
- Veröffentlicht 22.06.2023 05:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:11
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Word-wrap Project ≫ Word-wrap SwPlatformnode.js Version < 1.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.149 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| report@snyk.io | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.