kangax / kangax/html-minifier

SECURITY: CVE-2022-37620

Open
#1,137 1 comment 4 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
5k
Forks
577
PR merge metrics
No merged PRs in 30d

Description

When running MEND we see this
[CVE-2022-37620](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2022-37620)

https://nvd.nist.gov/vuln/detail/CVE-2022-37620

Seems like A Regular Expression Denial of Service (ReDoS) flaw

tnx for any help

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no source file, test, or entry point. Start by reading the linked CVE and NVD details, then use the MEND report to identify the affected JavaScript regular expression or dependency. Done means the reported ReDoS exposure is addressed and regression coverage verifies the fix.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.