Regular Expression Denial of Service in millisecond
Moderate severity
GitHub Reviewed
Published
Sep 22, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Sep 22, 2021
Published to the GitHub Advisory Database
Sep 22, 2021
Last updated
Jan 9, 2023
Versions of
millisecond
prior to 0.1.2 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.Proof of concept
Recommendation
Update to version 0.1.2 or later.
References