forwardemail / forwardemail/supertest
cookiejar Regular Expression Denial of Service via Cookie.parse function
Open
bug
- Dominant language
- JavaScript
- Stars
- 14.4k
- Forks
- 782
- PR merge metrics
- No merged PRs in 30d
Description
## Describe the bug
Due to the use of superagent 8.0.5, which uses cookiejar version 2.1.3, a vulnerability is present in the latest package, https://github.com/advisories/GHSA-h452-7996-h45h.
A simple fix would be to update superagent's version to the latest.
Contributor guide
Assessment
This issue has not been assessed yet.