editor-js / editor-js/list-legacy

vulnerable to Regular Expression Denial of Service

Open
#83 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
58
Forks
68
PR merge metrics
No merged PRs in 30d

Description

http-cache-semantics <4.1.1
Severity: high
http-cache-semantics vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-rc47-6667-2j5j
fix available via `npm audit fix`
node_modules/npm/node_modules/http-cache-semantics

1 high severity vulnerability

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by running npm audit and review the reported http-cache-semantics dependency under node_modules/npm. Run npm audit fix as suggested, then verify that the Regular Expression Denial of Service advisory and the high-severity vulnerability are no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.