A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2537 | A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU. |
Github GHSA |
GHSA-j377-2x76-558h | Improper Input Validation in is-email |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:01:59.394Z
Reserved: 2021-07-12T00:00:00
Link: CVE-2021-36716
No data.
Status : Modified
Published: 2021-07-14T16:15:07.860
Modified: 2024-11-21T06:13:57.973
Link: CVE-2021-36716
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA