CVE-2020-26309
Oct. 28, 2024, 1:58 p.m.
Tags
Product(s) Impacted
Validate.js
- 0.11.3 and prior
Description
Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available.
Weaknesses
CWE-1333
Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CWE ID: 1333Date
Published: Oct. 26, 2024, 9:15 p.m.
Last Modified: Oct. 28, 2024, 1:58 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security-advisories@github.com