forwardemail / forwardemail/supertest

cookiejar Regular Expression Denial of Service via Cookie.parse function

Open
#812 3 comments 3 reactions 0 assignees View on GitHub
bug
Dominant language
JavaScript
Stars
14.4k
Forks
782
PR merge metrics
No merged PRs in 30d

Description

## Describe the bug

Due to the use of superagent 8.0.5, which uses cookiejar version 2.1.3, a vulnerability is present in the latest package, https://github.com/advisories/GHSA-h452-7996-h45h.

A simple fix would be to update superagent's version to the latest.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.