CVE-2022-37620
7.5HIGHA Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.
Опубликовано: 10/31/2022Обновлено: 6/1/2025
Описание
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.
ИИ-АнализНа базе ИИ
Затронутые продукты
terserhtml-minifier-terser
kangaxhtml-minifier
Ссылки
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L1338Product
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L294Product
- https://github.com/kangax/html-minifier/issues/1135Issue TrackingMitigationThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-HTMLMINIFIER-3091181
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L1338Product
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L294Product
- https://github.com/kangax/html-minifier/issues/1135Issue TrackingMitigationThird Party Advisory