Loading HuntDB...

GHSA-333w-rxj3-f55r

GitHub Security Advisory

Regular Expression Denial Of Service in uri-js

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Affected versions of `uri-js` is susceptible to a regular expression denial of service vulnerability when user input is sent to the `.parse()` method.

## Recommendation

Update to v3.0.0 or later.

Affected Packages

npm uri-js
Affected versions: 0 (fixed in 3.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-333w-rxj3-f55r
Published
July 24, 2018 8:00 PM
Last Modified
April 22, 2024 7:37 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
uri-js
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.