Description
A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2537 | A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU. |
Github GHSA |
GHSA-j377-2x76-558h | Improper Input Validation in is-email |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:01:59.394Z
Reserved: 2021-07-12T00:00:00.000Z
Link: CVE-2021-36716
No data.
Status : Modified
Published: 2021-07-14T16:15:07.860
Modified: 2024-11-21T06:13:57.973
Link: CVE-2021-36716
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA