Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2020-26310

Oct. 28, 2024, 1:58 p.m.

Product(s) Impacted

Validate.js

Description

Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available.

Weaknesses

CWE-1333
Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

CWE ID: 1333

Date

Published: Oct. 26, 2024, 9:15 p.m.

Last Modified: Oct. 28, 2024, 1:58 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security-advisories@github.com

References

https://github.com/ security-advisories@github.com

https://securitylab.github.com/ security-advisories@github.com