描述
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.
AI分析AI驱动
受影响产品
terserhtml-minifier-terser
kangaxhtml-minifier
参考资料
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L1338Product
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L294Product
- https://github.com/kangax/html-minifier/issues/1135Issue TrackingMitigationThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-HTMLMINIFIER-3091181
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L1338Product
- https://github.com/kangax/html-minifier/blob/51ce10f4daedb1de483ffbcccecc41be1c873da2/src/htmlminifier.js#L294Product
- https://github.com/kangax/html-minifier/issues/1135Issue TrackingMitigationThird Party Advisory