GHSA-7f53-fmmv-mfjv
GitHub Security Advisory
Regular expression denial of service in react-native
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.
Affected Packages
npm
react-native
Affected versions:
0.59.0
(fixed in 0.62.3)
npm
react-native
Affected versions:
0.63.0
(fixed in 0.64.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.